d60f9eaa4f62f0ee84531d9aa633c5bb390ea0056953e58d80b9a62277dbe5c5

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2031-Mar-30 07:12:41
Detected languages English - United States
Debug artifacts kernel32.pdb
CompanyName Microsoft Corporation
FileDescription Windows NT BASE API Client DLL
FileVersion 10.0.19041.292 (WinBuild.160101.0800)
InternalName kernel32
LegalCopyright © Microsoft Corporation. All rights reserved.
OriginalFilename kernel32
ProductName Microsoft® Windows® Operating System
ProductVersion 10.0.19041.292

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: May have dropper capabilities:
  • CurrentControlSet\Services
Contains domain names:
  • http://schemas.microsoft.com
  • http://schemas.microsoft.com/SMI/2005/WindowsSettings
  • http://schemas.microsoft.com/SMI/2011/WindowsSettings
  • http://schemas.microsoft.com/SMI/2013/WindowsSettings
  • http://schemas.microsoft.com/SMI/2014/WindowsSettings
  • http://schemas.microsoft.com/SMI/2016/WindowsSettings
  • http://schemas.microsoft.com/SMI/2017/WindowsSettings
  • http://schemas.microsoft.com/SMI/2019/WindowsSettings
  • http://schemas.microsoft.com/SMI/2020/WindowsSettings
  • microsoft.com
  • schemas.microsoft.com
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Suspicious The PE is possibly packed. Unusual section name found: .didat
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LdrLoadDll
  • LoadLibraryExW
  • LoadLibraryExA
  • GetProcAddress
  • LoadLibraryW
  • LoadLibraryA
Functions which can be used for anti-debugging purposes:
  • NtQueryInformationProcess
  • DbgPrint
  • ZwQuerySystemInformation
  • NtQuerySystemInformation
  • SwitchToThread
  • CheckRemoteDebuggerPresent
Code injection capabilities:
  • CreateRemoteThread
  • CreateRemoteThreadEx
  • OpenProcess
  • WriteProcessMemory
  • VirtualAlloc
  • VirtualAllocEx
  • VirtualAllocExNuma
Code injection capabilities (process hollowing):
  • ResumeThread
  • SetThreadContext
  • WriteProcessMemory
  • Wow64SetThreadContext
Code injection capabilities (mapping injection):
  • CreateRemoteThread
  • CreateRemoteThreadEx
  • CreateFileMappingNumaW
  • MapViewOfFileEx
  • MapViewOfFile
  • CreateFileMappingW
Can access the registry:
  • RegDeleteValueA
  • RegSetValueExW
  • RegCreateKeyExA
  • RegSetValueExA
  • RegSetKeySecurity
  • RegSaveKeyExW
  • RegCloseKey
  • RegLoadAppKeyW
  • RegRestoreKeyW
  • RegRestoreKeyA
  • RegGetValueW
  • RegQueryValueExW
  • RegUnLoadKeyW
  • RegOpenKeyExW
  • RegCreateKeyExW
  • RegDeleteKeyExA
  • RegUnLoadKeyA
  • RegDeleteKeyExW
  • RegDeleteValueW
  • RegQueryValueExA
  • RegQueryInfoKeyW
  • RegQueryInfoKeyA
  • RegSaveKeyExA
  • RegOpenKeyExA
  • RegNotifyChangeKeyValue
  • RegLoadKeyW
  • RegLoadKeyA
  • RegGetValueA
  • RegGetKeySecurity
  • RegEnumKeyExA
  • RegEnumKeyExW
  • RegFlushKey
  • RegEnumValueW
  • RegEnumValueA
Possibly launches other programs:
  • CreateProcessInternalA
  • CreateProcessInternalW
  • CreateProcessAsUserW
  • CreateProcessAsUserA
  • CreateProcessW
  • CreateProcessA
Uses Windows's Native API:
  • NtEnumerateKey
  • NtTerminateProcess
  • NtMapUserPhysicalPagesScatter
  • NtDeleteValueKey
  • NtSetValueKey
  • NtQueryInstallUILanguage
  • NtQueryLicenseValue
  • NtMapViewOfSection
  • NtCreateSection
  • NtUnmapViewOfSection
  • NtQueryInformationThread
  • NtQueryEvent
  • NtRaiseHardError
  • NtQueryVolumeInformationFile
  • NtReplacePartitionUnit
  • NtQueryValueKey
  • NtQueryInformationToken
  • NtOpenProcessToken
  • NtSetInformationThread
  • NtOpenThreadToken
  • NtOpenKey
  • NtIsSystemResumeAutomatic
  • NtInitiatePowerAction
  • NtWaitForSingleObject
  • NtCreateEvent
  • NtFsControlFile
  • NtOpenFile
  • NtClose
  • NtQueryInformationFile
  • NtSetInformationFile
  • NtSetInformationDebugObject
  • NtSetSystemInformation
  • NtQueryInformationProcess
  • NtFindAtom
  • NtQueryInformationAtom
  • NtAddAtomEx
  • NtDeleteAtom
  • NtFlushKey
  • NtCreateKey
  • NtCreateFile
  • NtCreateJobSet
  • NtSetInformationJobObject
  • NtQueryInformationJobObject
  • NtCreateJobObject
  • NtAssignProcessToJobObject
  • NtTerminateJobObject
  • NtOpenJobObject
  • NtSetEaFile
  • NtSetSecurityObject
  • NtQueryEaFile
  • NtQuerySecurityObject
  • NtSetInformationProcess
  • NtQuerySection
  • NtFreeVirtualMemory
  • NtWriteFile
  • NtEnumerateValueKey
  • NtUnlockFile
  • NtReadFile
  • NtLockFile
  • NtAllocateVirtualMemory
  • NtQueryVirtualMemory
  • NtProtectVirtualMemory
  • NtCreateMailslotFile
  • NtQueryDirectoryFile
  • NtQueryWnfStateData
  • NtPowerInformation
  • NtGetDevicePowerState
  • NtSetThreadExecutionState
  • NtSetSystemEnvironmentValueEx
  • NtQuerySystemEnvironmentValueEx
  • NtSetVolumeInformationFile
  • NtDeviceIoControlFile
  • NtQueryAttributesFile
  • NtQueryFullAttributesFile
  • NtSetTimerResolution
  • NtQueryTimerResolution
  • NtReadVirtualMemory
  • NtWaitForMultipleObjects
  • NtClearEvent
  • NtApphelpCacheControl
  • ZwClose
  • ZwOpenFile
  • ZwOpenKey
  • ZwEnumerateKey
  • ZwQueryValueKey
  • ZwCreateFile
  • ZwQueryInformationFile
  • ZwCreateSection
  • ZwQueryDirectoryFile
  • ZwQuerySystemInformation
  • ZwUnmapViewOfSection
  • ZwMapViewOfSection
  • NtQuerySystemInformation
Can create temporary files:
  • CreateFileW
  • CreateFileA
  • GetTempPathW
  • GetTempPathA
Memory manipulation functions often used by packers:
  • VirtualAlloc
  • VirtualProtectEx
  • VirtualProtect
  • VirtualAllocEx
Functions related to the privilege level:
  • OpenProcessToken
  • DuplicateToken
Enumerates local disk drives:
  • GetDriveTypeA
  • GetDriveTypeW
  • GetLogicalDriveStringsW
  • GetVolumeInformationByHandleW
  • GetVolumeInformationW
  • GetVolumeInformationA
Manipulates other processes:
  • OpenProcess
  • WriteProcessMemory
  • ReadProcessMemory
Info The PE is digitally signed. Signer: Microsoft Windows
Issuer: Microsoft Windows Production PCA 2011
Safe VirusTotal score: 0/71 (Scanned on 2020-06-09 18:53:12) All the AVs think this file is safe.

Hashes

MD5 3f7de1ebec982b762839c8c192f4d4b1
SHA1 f6526b1313b335f4954a2bfce54a81037125d4e8
SHA256 d60f9eaa4f62f0ee84531d9aa633c5bb390ea0056953e58d80b9a62277dbe5c5
SHA3 f847adfcdc6ce64ae17bbc7569104ed1918c3ec3493bce26f6fc05f1bb05ca14
SSDeep 12288:XqnWY0FkshGbngdMbfklK6mCM6rXoLjvTkjYLo4P6HDgIrHYDP58/SaSbmz6F:XeWYy3dMbEnmCLTAjvgm8jbrHYF8/Sa
Imports Hash bb71e3d6d784888547e9dfa072581e1e

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xf0

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2031-Mar-30 07:12:41
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x7d400
SizeOfInitializedData 0x3a400
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000017070 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x180000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion A.0
ImageVersion A.0
SubsystemVersion A.0
Win32VersionValue 0
SizeOfImage 0xbd000
SizeOfHeaders 0x400
Checksum 0xbcf26
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
SizeofStackReserve 0x40000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 50844e3f56761b3a89ba7c1e1c50e26c
SHA1 1f7f1815f2ea3448b28d76a57da60ee374423975
SHA256 856a7065ae89893a0ad0b93f4af61cec3613fedf8fbfcd0bedddcec7b4fc4303
SHA3 2bfb18de33f1c857b84a1a802666eef192c960def7bfbc430f6f44702538f4a1
VirtualSize 0x7d26b
VirtualAddress 0x1000
SizeOfRawData 0x7d400
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.28942

.rdata

MD5 67fd4483f9773794ac223fea7a18a6f0
SHA1 3cd5c5c69e1e11fd3fed6dcd562a27dacc6ad5d9
SHA256 2dbd472b4bddcf792c0c71a30af9e9c3e0fd9eff06472cfac9e23bae197df37b
SHA3 74ef62da8006b29605dc717d6a4307254450fe485aa4ea9968b7e61618dd049a
VirtualSize 0x32c40
VirtualAddress 0x7f000
SizeOfRawData 0x32e00
PointerToRawData 0x7d800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.66453

.data

MD5 896659efa6a4a4e360f64c78e6dfb3ce
SHA1 82ff3a3210de87e3bfb3febe8f179e562a0c3ea9
SHA256 c89d2882e2b94c59d9b7b94358bfcb81d6b22ab76b173a4b9c404650e420e926
SHA3 002b7fec561810b07253cafec91e1b6eb93a416444a15ddf0696da6dae7f6267
VirtualSize 0x121c
VirtualAddress 0xb2000
SizeOfRawData 0x600
PointerToRawData 0xb0600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.61265

.pdata

MD5 6efba0eb1e7ea9becff8c980ddadc0eb
SHA1 694f2aeecf75906507891587128dfde074285b45
SHA256 bd36a985280a31577d21c42c313d2a2bd5348ccdb1b028c9c027ce6da7f8e4a1
SHA3 e07ad00f1e6ea93bce7670a39a6904a2afba6a47ebbbd8af8107e2c3914b7dd3
VirtualSize 0x555c
VirtualAddress 0xb4000
SizeOfRawData 0x5600
PointerToRawData 0xb0c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.87664

.didat

MD5 7b3ad2be1e0a8b4ca50c5e2213888745
SHA1 0dbb3f1ef55ee8a5b48a8fde8b1ee06694e98852
SHA256 801407f325f51ea3d99f03d41177ca4b3c603020c115812dc04e055c9b5593fe
SHA3 2ff2348e0e076a6a1636ba213f9c7c4e14e47e12bebf39c77e1ac32fb8426bf3
VirtualSize 0x68
VirtualAddress 0xba000
SizeOfRawData 0x200
PointerToRawData 0xb6200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.830536

.rsrc

MD5 1503000a9583e54a1954b61618d28118
SHA1 49b4066a50ee86b93461dbb5ed30b767eb3031ea
SHA256 e55254d8e9ebc7fb8805e07c90301c81173595240485a9f22416fad0d298b267
SHA3 f78aa0c65aa4466608b014066e06866dcf706aea1e781b82bd4de5ec00a7fb04
VirtualSize 0x520
VirtualAddress 0xbb000
SizeOfRawData 0x600
PointerToRawData 0xb6400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 2.97643

.reloc

MD5 d0f2c6b69902a9b83e9f935ead907a5d
SHA1 c05af27135b152e72daf5a4d716c7d2a75e000cd
SHA256 17da1c4b3f07bf70448ec9654d7786fb7af972bb851fe54c1c198b693b1e06ff
SHA3 fc350ed3fa191ad27ae95b1193cf93ac4abe6917238dfd748c36042e90d0837b
VirtualSize 0x2fc
VirtualAddress 0xbc000
SizeOfRawData 0x400
PointerToRawData 0xb6a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.61283

Imports

api-ms-win-core-rtlsupport-l1-1-0.dll RtlCaptureContext
RtlRaiseException
RtlVirtualUnwind
RtlRestoreContext
RtlLookupFunctionEntry
RtlInstallFunctionTableCallback
RtlCompareMemory
RtlDeleteFunctionTable
RtlAddFunctionTable
RtlPcToFileHeader
RtlUnwind
RtlCaptureStackBackTrace
RtlUnwindEx
ntdll.dll _wcslwr
RtlGetUILanguageInfo
EtwEventEnabled
RtlpConvertLCIDsToCultureNames
NtEnumerateKey
RtlIntegerToUnicodeString
RtlTimeToTimeFields
RtlTimeFieldsToTime
RtlUnhandledExceptionFilter
NtTerminateProcess
wcsncmp
wcsncpy
LdrFindResourceEx_U
RtlReadThreadProfilingData
RtlQueryThreadProfiling
RtlDisableThreadProfiling
RtlNtStatusToDosErrorNoTeb
RtlEnableThreadProfiling
NtMapUserPhysicalPagesScatter
RtlDecodeSystemPointer
bsearch
RtlComputeImportTableHash
RtlFindActivationContextSectionGuid
RtlQueryActivationContextApplicationSettings
RtlSubAuthorityCountSid
LdrResFindResourceDirectory
RtlQueryInformationActivationContext
RtlSetThreadPreferredUILanguages
TpQueryPoolStackInformation
TpAllocPool
TpSetPoolMinThreads
TpSetPoolStackInformation
TpAllocWait
NtDeleteValueKey
NtSetValueKey
towlower
RtlLCIDToCultureName
RtlSizeHeap
RtlpConvertCultureNamesToLCIDs
NtQueryInstallUILanguage
EtwEventUnregister
EtwEventWrite
EtwEventRegister
RtlExpandEnvironmentStrings_U
RtlPublishWnfStateData
NtQueryLicenseValue
_wtol
memmove_s
RtlUnicodeStringToInteger
RtlGUIDFromString
RtlMultiAppendUnicodeStringBuffer
swprintf_s
RtlImageNtHeaderEx
NtMapViewOfSection
NtCreateSection
RtlDosPathNameToNtPathName_U_WithStatus
RtlGetActiveActivationContext
RtlDeactivateActivationContext
RtlActivateActivationContext
RtlZombifyActivationContext
RtlReleaseActivationContext
RtlAddRefActivationContext
RtlCreateActivationContext
RtlGetLengthWithoutLastFullDosOrNtPathElement
RtlpApplyLengthFunction
RtlGetFullPathName_U
RtlDoesFileExists_U
RtlDetermineDosPathNameType_U
RtlpEnsureBufferSize
DbgPrintEx
NtUnmapViewOfSection
RtlQueryPackageClaims
tolower
atol
toupper
isdigit
NtQueryInformationThread
RtlEnterUmsSchedulingMode
RtlCreateUmsThreadContext
RtlDeleteUmsThreadContext
RtlSetUmsThreadInformation
sin
RtlGetNextUmsListItem
RtlGetCurrentUmsThread
RtlDeleteUmsCompletionList
RtlUmsThreadYield
RtlExecuteUmsThread
RtlGetUmsCompletionListEvent
RtlDequeueUmsCompletionListItems
RtlSetLastWin32ErrorAndNtStatusFromNtStatus
RtlCreateUmsCompletionList
RtlDestroyEnvironment
RtlCreateEnvironmentEx
RtlCreateEnvironment
NtQueryEvent
RtlCreateUnicodeString
NtRaiseHardError
RtlFreeAnsiString
RtlFreeOemString
RtlGetCurrentDirectory_U
wcsrchr
_wcsnicmp
RtlUnicodeStringToOemString
NtQueryVolumeInformationFile
CsrFreeCaptureBuffer
CsrAllocateMessagePointer
CsrAllocateCaptureBuffer
RtlEqualUnicodeString
RtlUnicodeStringToAnsiString
RtlExitUserThread
RtlAddIntegrityLabelToBoundaryDescriptor
RtlQueryProtectedPolicy
NtReplacePartitionUnit
RtlCompareUnicodeString
RtlExitUserProcess
RtlInitUnicodeStringEx
RtlQueryPackageIdentity
EtwEventWriteNoRegistration
RtlWow64LogMessageInEventLogger
LdrUnloadDll
LdrGetProcedureAddress
LdrLoadDll
RtlAppendUnicodeToString
RtlAppendUnicodeStringToString
RtlFormatCurrentUserKeyPath
NtQueryValueKey
RtlEqualSid
RtlSubAuthoritySid
RtlInitializeSid
NtQueryInformationToken
NtOpenProcessToken
NtSetInformationThread
NtOpenThreadToken
RtlReleaseSRWLockExclusive
RtlQueryRegistryValuesEx
NtOpenKey
RtlAcquireSRWLockExclusive
RtlAnsiStringToUnicodeString
RtlxAnsiStringToUnicodeSize
RtlInitAnsiStringEx
NtIsSystemResumeAutomatic
NtInitiatePowerAction
RtlIsNameLegalDOS8Dot3
RtlGetCurrentProcessorNumberEx
NtWaitForSingleObject
NtCreateEvent
RtlSetSearchPathMode
LdrGetDllDirectory
RtlUnlockHeap
RtlGetUserInfoHeap
RtlLockHeap
RtlDeregisterSecureMemoryCacheCallback
RtlRegisterSecureMemoryCacheCallback
RtlCompactHeap
NtFsControlFile
NtOpenFile
NtClose
LdrAddRefDll
NtQueryInformationFile
NtSetInformationFile
wcscpy_s
RtlGetActiveConsoleId
RtlDeactivateActivationContextUnsafeFast
RtlActivateActivationContextUnsafeFast
RtlNtStatusToDosError
RtlFreeUnicodeString
RtlWow64GetThreadSelectorEntry
NtSetInformationDebugObject
DbgUiGetThreadDebugObject
DbgUiIssueRemoteBreakin
NtSetSystemInformation
NtQueryInformationProcess
RtlSetCurrentTransaction
RtlGetCurrentTransaction
RtlSetLastWin32Error
CsrClientCallServer
LdrDisableThreadCalloutsForDll
RtlGetSuiteMask
TpAllocTimer
TpAllocIoCompletion
TpAllocWork
TpCallbackMayRunLong
TpAllocCleanupGroup
RtlQueryUmsThreadInformation
TpSimpleTryPost
CsrVerifyRegion
RtlCharToInteger
RtlInitAnsiString
RtlUpcaseUnicodeChar
RtlUnicodeToMultiByteSize
RtlDestroyAtomTable
NtFindAtom
NtQueryInformationAtom
RtlAddAtomToAtomTable
NtAddAtomEx
NtDeleteAtom
RtlCreateAtomTable
RtlDeleteAtomFromAtomTable
RtlLookupAtomInAtomTable
RtlQueryAtomInAtomTable
RtlDnsHostNameToComputerName
RtlPrefixString
NtFlushKey
_memicmp
RtlxUnicodeStringToAnsiSize
RtlEnterCriticalSection
wcschr
wcsstr
RtlLeaveCriticalSection
NtCreateKey
NtCreateFile
RtlCreateUnicodeStringFromAsciiz
wcsncpy_s
wcscspn
NtCreateJobSet
RtlReleasePrivilege
NtSetInformationJobObject
NtQueryInformationJobObject
NtCreateJobObject
RtlAcquirePrivilege
NtAssignProcessToJobObject
NtTerminateJobObject
NtOpenJobObject
RtlLengthSecurityDescriptor
NtSetEaFile
NtSetSecurityObject
NtQueryEaFile
NtQuerySecurityObject
LdrQueryImageFileKeyOption
LdrOpenImageFileOptionsKey
RtlQueryElevationFlags
NtSetInformationProcess
RtlRaiseStatus
NtQuerySection
NtFreeVirtualMemory
NtWriteFile
NtEnumerateValueKey
RtlEqualString
RtlUnicodeToMultiByteN
strncpy_s
NtUnlockFile
RtlDosPathNameToNtPathName_U
NtReadFile
NtLockFile
RtlCopyUnicodeString
CsrCaptureMessageString
RtlIsTextUnicode
NtAllocateVirtualMemory
RtlGetLongestNtPathLength
RtlPrefixUnicodeString
RtlMultiByteToUnicodeN
RtlMultiByteToUnicodeSize
RtlDosPathNameToRelativeNtPathName_U
RtlReleaseRelativeName
RtlSetIoCompletionCallback
RtlDeregisterWait
RtlRegisterWait
RtlImageDirectoryEntryToData
NtQueryVirtualMemory
RtlCreateBoundaryDescriptor
NtProtectVirtualMemory
RtlGetThreadErrorMode
NtCreateMailslotFile
RtlDestroyQueryDebugBuffer
RtlQueryProcessDebugInformation
RtlCreateQueryDebugBuffer
NtQueryDirectoryFile
strcpy_s
RtlFindActivationContextSectionString
LdrSetDllDirectory
LdrFindResource_U
RtlSwitchedVVI
NtQueryWnfStateData
NtPowerInformation
NtGetDevicePowerState
NtSetThreadExecutionState
NtSetSystemEnvironmentValueEx
NtQuerySystemEnvironmentValueEx
RtlInitString
NtSetVolumeInformationFile
NtDeviceIoControlFile
RtlIsValidHandle
RtlAllocateHandle
RtlReAllocateHeap
RtlFreeHandle
RtlSetUserValueHeap
RtlUnsubscribeWnfStateChangeNotification
RtlSubscribeWnfStateChangeNotification
RtlQueryWnfStateData
strchr
RtlSetEnvironmentStrings
RtlOemStringToUnicodeString
wcscat_s
RtlAllocateAndInitializeSid
RtlQueryEnvironmentVariable_U
NtQueryAttributesFile
RtlFreeSid
strrchr
NtQueryFullAttributesFile
TpCaptureCaller
RtlWow64EnableFsRedirection
_stricmp
NtSetTimerResolution
NtQueryTimerResolution
RtlGetAppContainerSidType
RtlConvertSidToUnicodeString
RtlSetEnvironmentVariable
RtlGetAppContainerParent
RtlQueryEnvironmentVariable
CsrCaptureMessageMultiUnicodeStringsInPlace
wcsnlen
strcat_s
strnlen
NlsMbCodePageTag
RtlRunOnceExecuteOnce
RtlInitializeCriticalSection
RtlGetThreadPreferredUILanguages
NtReadVirtualMemory
LdrResSearchResource
_strnicmp
strncmp
RtlTryAcquirePebLock
RtlReleasePebLock
RtlEncodeSystemPointer
RtlGetNtSystemRoot
NtWaitForMultipleObjects
NtClearEvent
RtlWerpReportException
DbgPrint
RtlGetDeviceFamilyInfoEnum
RtlHashUnicodeString
NtApphelpCacheControl
RtlGetFullPathName_UEx
ZwClose
ZwOpenFile
ZwOpenKey
ZwEnumerateKey
ZwQueryValueKey
ZwCreateFile
ZwQueryInformationFile
ZwCreateSection
ZwQueryDirectoryFile
RtlNtPathNameToDosPathName
RtlGetNativeSystemInformation
ZwQuerySystemInformation
ZwUnmapViewOfSection
ZwMapViewOfSection
VerSetConditionMask
RtlVerifyVersionInfo
RtlGetVersion
RtlGetCurrentServiceSessionId
LdrQueryImageFileExecutionOptions
RtlInitUnicodeString
_vsnwprintf
RtlSetProtectedPolicy
LdrSetDllManifestProber
RtlSetThreadPoolStartFunc
RtlImageNtHeader
NtQuerySystemInformation
RtlFreeHeap
RtlSetDaclSecurityDescriptor
RtlSetGroupSecurityDescriptor
RtlSetOwnerSecurityDescriptor
RtlCreateSecurityDescriptor
RtlAddAccessAllowedAce
RtlCreateAcl
RtlAllocateHeap
_wcsicmp
__C_specific_handler
memmove
RtlGetPersistedStateLocation
_local_unwind
cos
floor
memcmp
memcpy
memset
wcscmp
KERNELBASE.dll GetLocaleInfoHelper
BaseFormatObjectAttributes
GetVolumeNameForVolumeMountPointW
lstrcmpW
lstrcmpiW
GetRegistryExtensionFlags
KernelBaseGetGlobalData
GlobalFree
LoadStringBaseExW
GetUnicodeStringToEightBitStringRoutine
GetUnicodeStringToEightBitSizeRoutine
CompareStringA
GetNamedPipeAttribute
AppXPreCreationExtension
AppXPostSuccessExtension
AppXReleaseAppXContext
AreFileApisANSI
CreateProcessInternalA
CreateProcessInternalW
CreateProcessAsUserW
CreateProcessAsUserA
EnumLanguageGroupLocalesW
AppContainerLookupMoniker
EnumSystemLanguageGroupsW
EnumSystemLocalesEx
PackageIdFromFullName
GetPackageFullName
GetCurrentPackageFullName
ClosePackageInfo
AppXGetOSMaxVersionTested
GetPackageTargetPlatformProperty
GetTargetPlatformContext
OpenPackageInfoByFullNameForUser
AppContainerFreeMemory
BasepNotifyTrackingService
MoveFileWithProgressTransactedW
BasepAdjustObjectAttributesForPrivateNamespace
GetEightBitStringToUnicodeStringRoutine
GetStringTableEntry
CheckGroupPolicyEnabled
OpenRegKey
InternalLcidToName
NlsIsUserDefaultLocale
GetPtrCalDataArray
GetUserOverrideString
GetPtrCalData
Internal_EnumCalendarInfo
Internal_EnumLanguageGroupLocales
Internal_EnumSystemCodePages
Internal_EnumDateFormats
Internal_EnumUILanguages
Internal_EnumSystemLanguageGroups
NlsValidateLocale
Internal_EnumTimeFormats
GetNamedLocaleHashNode
GetUserOverrideWord
EnumUILanguagesW
GetCalendar
BaseDllFreeResourceId
BaseDllMapResourceIdW
CheckAllowDecryptedRemoteDestinationPolicy
PrivCopyFileExW
NotifyMountMgr
LCIDToLocaleName
GetUserDefaultLocaleName
GetSystemDefaultLocaleName
GetEraNameCountedString
FatalAppExitW
FatalAppExitA
lstrlenW
lstrlenA
lstrcpynW
lstrcpynA
Sleep
SetFileApisToOEM
SetFileApisToANSI
PulseEvent
MapViewOfFileExNuma
LocalUnlock
LocalReAlloc
LocalLock
LocalAlloc
HeapSummary
GlobalAlloc
GetUserDefaultUILanguage
GetSystemDefaultUILanguage
GetStringTypeA
GetProcAddressForCaller
BaseGetNamedObjectDirectory
api-ms-win-core-processthreads-l1-1-0.dll SetProcessShutdownParameters
SetPriorityClass
ResumeThread
QueueUserAPC
OpenThread
GetThreadPriorityBoost
GetThreadPriority
GetThreadId
SetThreadPriority
SetThreadPriorityBoost
SetThreadStackGuarantee
SuspendThread
SwitchToThread
TerminateProcess
TerminateThread
TlsAlloc
TlsFree
TlsSetValue
SetProcessAffinityUpdateMode
QueryProcessAffinityUpdateMode
GetStartupInfoW
GetProcessTimes
DeleteProcThreadAttributeList
UpdateProcThreadAttribute
InitializeProcThreadAttributeList
CreateRemoteThread
GetProcessId
GetProcessIdOfThread
GetPriorityClass
GetProcessVersion
GetExitCodeThread
CreateRemoteThreadEx
CreateProcessW
CreateProcessA
GetExitCodeProcess
OpenProcessToken
GetCurrentProcessId
GetCurrentProcess
ProcessIdToSessionId
api-ms-win-core-processthreads-l1-1-3.dll SetThreadIdealProcessor
SetProcessInformation
GetProcessInformation
GetProcessShutdownParameters
api-ms-win-core-processthreads-l1-1-2.dll GetThreadInformation
GetProcessPriorityBoost
GetThreadIOPendingFlag
SetProcessPriorityBoost
SetThreadInformation
GetSystemTimes
api-ms-win-core-processthreads-l1-1-1.dll IsProcessorFeaturePresent
SetThreadContext
GetThreadTimes
GetThreadIdealProcessorEx
GetThreadContext
GetProcessHandleCount
GetProcessMitigationPolicy
SetProcessMitigationPolicy
FlushInstructionCache
SetThreadIdealProcessorEx
OpenProcess
api-ms-win-core-registry-l1-1-0.dll RegDeleteValueA
RegSetValueExW
RegCreateKeyExA
RegSetValueExA
RegDeleteTreeW
RegCopyTreeW
RegSetKeySecurity
RegSaveKeyExW
RegCloseKey
RegLoadAppKeyW
RegRestoreKeyW
RegRestoreKeyA
RegGetValueW
RegQueryValueExW
RegUnLoadKeyW
RegOpenKeyExW
RegCreateKeyExW
RegDeleteKeyExA
RegUnLoadKeyA
RegDeleteKeyExW
RegDeleteValueW
RegQueryValueExA
RegQueryInfoKeyW
RegQueryInfoKeyA
RegOpenUserClassesRoot
RegSaveKeyExA
RegOpenKeyExA
RegOpenCurrentUser
RegNotifyChangeKeyValue
RegLoadMUIStringW
RegLoadMUIStringA
RegLoadKeyW
RegLoadKeyA
RegGetValueA
RegGetKeySecurity
RegDisablePredefinedCacheEx
RegEnumKeyExA
RegEnumKeyExW
RegFlushKey
RegEnumValueW
RegEnumValueA
RegDeleteTreeA
api-ms-win-core-heap-l1-1-0.dll HeapFree
HeapReAlloc
HeapAlloc
HeapWalk
HeapValidate
HeapUnlock
HeapSetInformation
HeapQueryInformation
HeapLock
GetProcessHeap
HeapDestroy
HeapCreate
HeapCompact
GetProcessHeaps
api-ms-win-core-heap-l2-1-0.dll LocalFree
api-ms-win-core-memory-l1-1-1.dll GetWriteWatch
ResetWriteWatch
SetSystemFileCacheSize
SetProcessWorkingSetSizeEx
QueryMemoryResourceNotification
VirtualLock
CreateFileMappingNumaW
GetSystemFileCacheSize
GetProcessWorkingSetSizeEx
GetLargePageMinimum
CreateMemoryResourceNotification
VirtualUnlock
api-ms-win-core-memory-l1-1-0.dll OpenFileMappingW
MapViewOfFileEx
MapViewOfFile
VirtualFreeEx
WriteProcessMemory
VirtualAlloc
ReadProcessMemory
VirtualQuery
VirtualProtectEx
VirtualProtect
VirtualFree
UnmapViewOfFile
FlushViewOfFile
VirtualAllocEx
VirtualQueryEx
CreateFileMappingW
api-ms-win-core-memory-l1-1-2.dll VirtualAllocExNuma
AllocateUserPhysicalPages
AllocateUserPhysicalPagesNuma
FreeUserPhysicalPages
MapUserPhysicalPages
RegisterBadMemoryNotification
UnregisterBadMemoryNotification
GetMemoryErrorHandlingCapabilities
api-ms-win-core-handle-l1-1-0.dll SetHandleInformation
CloseHandle
GetHandleInformation
DuplicateHandle
api-ms-win-core-synch-l1-1-0.dll SetEvent
ResetEvent
ReleaseSemaphore
ReleaseMutex
InitializeCriticalSection
DeleteCriticalSection
SetWaitableTimer
WaitForMultipleObjectsEx
WaitForSingleObject
WaitForSingleObjectEx
EnterCriticalSection
LeaveCriticalSection
SleepEx
OpenWaitableTimerW
OpenSemaphoreW
OpenMutexW
CancelWaitableTimer
CreateEventA
CreateEventExA
CreateEventExW
CreateEventW
CreateMutexA
CreateMutexExA
CreateMutexExW
CreateMutexW
CreateSemaphoreExW
OpenEventW
CreateWaitableTimerExW
InitializeCriticalSectionAndSpinCount
InitializeCriticalSectionEx
OpenEventA
api-ms-win-core-synch-l1-2-1.dll WaitForMultipleObjects
CreateSemaphoreW
api-ms-win-core-synch-l1-2-0.dll InitOnceExecuteOnce
DeleteSynchronizationBarrier
InitializeSynchronizationBarrier
EnterSynchronizationBarrier
SignalObjectAndWait
api-ms-win-core-file-l1-1-0.dll FindFirstChangeNotificationW
FindFirstFileA
FindFirstFileExA
FindFirstFileExW
WriteFileEx
FindFirstFileW
FindFirstVolumeW
FindNextChangeNotification
FindNextFileA
FindFirstChangeNotificationA
FindCloseChangeNotification
WriteFileGather
FindNextFileW
FindNextVolumeW
FindVolumeClose
FlushFileBuffers
GetDiskFreeSpaceA
GetDiskFreeSpaceExA
GetDiskFreeSpaceExW
GetDiskFreeSpaceW
GetDriveTypeA
GetDriveTypeW
GetFileAttributesA
GetFileAttributesExA
GetFileAttributesExW
GetFileAttributesW
FindClose
GetFileInformationByHandle
FileTimeToLocalFileTime
DeleteVolumeMountPointW
DeleteFileW
DeleteFileA
DefineDosDeviceW
CreateFileW
CreateFileA
WriteFile
CreateDirectoryW
CreateDirectoryA
CompareFileTime
GetFinalPathNameByHandleA
GetFinalPathNameByHandleW
GetFullPathNameA
GetFullPathNameW
GetLogicalDriveStringsW
UnlockFileEx
GetTempFileNameW
UnlockFile
SetFileValidData
SetFileTime
GetVolumeInformationByHandleW
GetVolumeInformationW
GetVolumePathNameW
SetFilePointerEx
LocalFileTimeToFileTime
LockFile
LockFileEx
QueryDosDeviceW
ReadFile
ReadFileEx
ReadFileScatter
GetFileSize
RemoveDirectoryA
RemoveDirectoryW
GetFileSizeEx
GetFileTime
GetFileType
SetEndOfFile
SetFileAttributesA
SetFilePointer
SetFileInformationByHandle
SetFileAttributesW
api-ms-win-core-file-l1-2-0.dll CreateFile2
GetVolumePathNamesForVolumeNameW
GetTempPathW
api-ms-win-core-file-l1-2-2.dll FindFirstStreamW
GetTempFileNameA
GetTempPathA
FindNextFileNameW
FindFirstFileNameW
GetVolumeInformationA
api-ms-win-core-file-l1-2-1.dll SetFileIoOverlappedRange
GetCompressedFileSizeA
GetCompressedFileSizeW
api-ms-win-core-delayload-l1-1-0.dll DelayLoadFailureHook
api-ms-win-core-io-l1-1-0.dll DeviceIoControl
PostQueuedCompletionStatus
GetQueuedCompletionStatusEx
GetQueuedCompletionStatus
GetOverlappedResult
CreateIoCompletionPort
CancelIoEx
api-ms-win-core-io-l1-1-1.dll CancelIo
CancelSynchronousIo
api-ms-win-core-job-l1-1-0.dll IsProcessInJob
api-ms-win-core-threadpool-legacy-l1-1-0.dll CreateTimerQueueTimer
CreateTimerQueue
DeleteTimerQueueTimer
DeleteTimerQueueEx
UnregisterWaitEx
QueueUserWorkItem
ChangeTimerQueueTimer
api-ms-win-core-threadpool-private-l1-1-0.dll RegisterWaitForSingleObjectEx
api-ms-win-core-largeinteger-l1-1-0.dll MulDiv
api-ms-win-core-libraryloader-l1-2-2.dll EnumResourceNamesW
api-ms-win-core-libraryloader-l1-2-0.dll GetModuleFileNameA
FreeResource
FreeLibraryAndExitThread
GetModuleFileNameW
GetModuleHandleA
GetModuleHandleW
LoadLibraryExW
GetModuleHandleExA
GetModuleHandleExW
EnumResourceTypesExW
EnumResourceTypesExA
EnumResourceNamesExA
EnumResourceLanguagesExW
EnumResourceLanguagesExA
DisableThreadLibraryCalls
EnumResourceNamesExW
SizeofResource
LockResource
LoadResource
LoadLibraryExA
FindResourceExW
FreeLibrary
GetProcAddress
FindStringOrdinal
api-ms-win-core-libraryloader-l1-2-1.dll LoadLibraryW
FindResourceW
LoadLibraryA
api-ms-win-core-libraryloader-l2-1-0.dll LoadPackagedLibrary
api-ms-win-core-namedpipe-l1-2-2.dll CallNamedPipeW
api-ms-win-core-namedpipe-l1-1-0.dll TransactNamedPipe
PeekNamedPipe
WaitNamedPipeW
ConnectNamedPipe
CreateNamedPipeW
CreatePipe
DisconnectNamedPipe
GetNamedPipeClientComputerNameW
SetNamedPipeHandleState
api-ms-win-core-namedpipe-l1-2-1.dll GetNamedPipeHandleStateW
api-ms-win-core-datetime-l1-1-0.dll GetTimeFormatA
GetTimeFormatW
GetDateFormatW
GetDateFormatA
api-ms-win-core-datetime-l1-1-1.dll GetTimeFormatEx
GetDateFormatEx
api-ms-win-core-datetime-l1-1-2.dll GetDurationFormatEx
api-ms-win-core-sysinfo-l1-2-0.dll SetComputerNameExW
SetSystemTime
GetSystemFirmwareTable
EnumSystemFirmwareTables
GetSystemTimePreciseAsFileTime
GetNativeSystemInfo
GetProductInfo
api-ms-win-core-sysinfo-l1-1-0.dll GetVersionExW
GetWindowsDirectoryA
GetWindowsDirectoryW
GetSystemTimeAsFileTime
GlobalMemoryStatusEx
SetLocalTime
GetLogicalProcessorInformation
GetVersionExA
GetSystemTime
GetSystemInfo
GetLocalTime
GetComputerNameExW
GetLogicalProcessorInformationEx
GetTickCount
GetComputerNameExA
GetSystemTimeAdjustment
GetVersion
api-ms-win-core-sysinfo-l1-2-3.dll SetComputerNameExA
SetComputerNameA
SetComputerNameW
api-ms-win-core-sysinfo-l1-2-1.dll DnsHostnameToComputerNameExW
GetPhysicallyInstalledSystemMemory
SetComputerNameEx2W
api-ms-win-core-timezone-l1-1-0.dll FileTimeToSystemTime
GetTimeZoneInformation
GetTimeZoneInformationForYear
SystemTimeToFileTime
TzSpecificLocalTimeToSystemTime
GetDynamicTimeZoneInformation
SetDynamicTimeZoneInformation
SetTimeZoneInformation
SystemTimeToTzSpecificLocalTime
api-ms-win-core-localization-l1-2-0.dll FindNLSStringEx
IsValidLocaleName
LCMapStringEx
LocaleNameToLCID
ResolveLocaleName
SetCalendarInfoW
SetThreadLocale
IdnToUnicode
LCMapStringW
LCMapStringA
IsValidLocale
IsValidLanguageGroup
IsValidCodePage
ConvertDefaultLocale
IsNLSDefinedString
IsDBCSLeadByteEx
IsDBCSLeadByte
GetUserDefaultLCID
GetUserDefaultLangID
VerLanguageNameW
VerLanguageNameA
SetLocaleInfoW
IdnToAscii
GetUserPreferredUILanguages
GetUILanguageInfo
GetThreadUILanguage
SetProcessPreferredUILanguages
GetThreadPreferredUILanguages
GetSystemPreferredUILanguages
GetNLSVersionEx
GetLocaleInfoEx
GetFileMUIPath
GetFileMUIInfo
GetThreadLocale
GetSystemDefaultLCID
GetSystemDefaultLangID
GetProcessPreferredUILanguages
GetCalendarInfoEx
GetCalendarInfoW
EnumSystemLocalesA
EnumSystemLocalesW
FindNLSString
FormatMessageA
FormatMessageW
GetACP
GetCPInfo
GetCPInfoExW
GetNLSVersion
IsValidNLSVersion
SetThreadPreferredUILanguages
SetThreadUILanguage
GetLocaleInfoA
GetLocaleInfoW
GetOEMCP
api-ms-win-core-processsnapshot-l1-1-0.dll PssWalkMarkerFree
PssWalkMarkerSeekToBeginning
PssWalkMarkerSetPosition
PssWalkMarkerGetPosition
PssDuplicateSnapshot
PssWalkSnapshot
PssQuerySnapshot
PssFreeSnapshot
PssWalkMarkerCreate
PssCaptureSnapshot
api-ms-win-core-processenvironment-l1-1-0.dll GetEnvironmentVariableW
GetEnvironmentStrings
SetCurrentDirectoryA
ExpandEnvironmentStringsW
FreeEnvironmentStringsA
GetCommandLineW
FreeEnvironmentStringsW
GetCommandLineA
SearchPathW
SetCurrentDirectoryW
GetStdHandle
GetEnvironmentVariableA
SetEnvironmentStringsW
GetEnvironmentStringsW
GetCurrentDirectoryW
ExpandEnvironmentStringsA
GetCurrentDirectoryA
SetEnvironmentVariableA
SetEnvironmentVariableW
SetStdHandle
SetStdHandleEx
api-ms-win-core-processenvironment-l1-2-0.dll NeedCurrentDirectoryForExePathW
SearchPathA
NeedCurrentDirectoryForExePathA
api-ms-win-core-string-l1-1-0.dll CompareStringEx
WideCharToMultiByte
MultiByteToWideChar
GetStringTypeW
CompareStringW
GetStringTypeExW
CompareStringOrdinal
FoldStringW
api-ms-win-core-debug-l1-1-1.dll WaitForDebugEvent
CheckRemoteDebuggerPresent
ContinueDebugEvent
DebugActiveProcessStop
DebugActiveProcess
api-ms-win-core-debug-l1-1-0.dll OutputDebugStringW
IsDebuggerPresent
OutputDebugStringA
DebugBreak
api-ms-win-core-errorhandling-l1-1-0.dll GetErrorMode
UnhandledExceptionFilter
RaiseException
SetErrorMode
SetUnhandledExceptionFilter
GetLastError
SetLastError
api-ms-win-core-errorhandling-l1-1-3.dll GetThreadErrorMode
SetThreadErrorMode
api-ms-win-core-fibers-l1-1-0.dll FlsGetValue
FlsAlloc
FlsSetValue
FlsFree
api-ms-win-core-util-l1-1-0.dll Beep
api-ms-win-core-profile-l1-1-0.dll QueryPerformanceCounter
QueryPerformanceFrequency
api-ms-win-security-base-l1-1-0.dll CreateWellKnownSid
GetTokenInformation
FreeSid
AllocateAndInitializeSid
EqualSid
DuplicateToken
AccessCheck
api-ms-win-security-base-l1-2-0.dll CheckTokenMembershipEx
CheckTokenCapability
SetCachedSigningLevel
GetAppContainerAce
AddScopedPolicyIDAce
AddResourceAttributeAce
GetCachedSigningLevel
api-ms-win-security-appcontainer-l1-1-0.dll GetAppContainerNamedObjectPath
api-ms-win-core-comm-l1-1-0.dll SetCommBreak
SetCommConfig
GetCommTimeouts
GetCommState
WaitCommEvent
GetCommModemStatus
GetCommMask
GetCommConfig
EscapeCommFunction
ClearCommError
GetCommProperties
TransmitCommChar
SetupComm
SetCommTimeouts
SetCommState
SetCommMask
PurgeComm
ClearCommBreak
api-ms-win-core-realtime-l1-1-0.dll QueryIdleProcessorCycleTimeEx
QueryIdleProcessorCycleTime
QueryProcessCycleTime
QueryThreadCycleTime
QueryUnbiasedInterruptTime
api-ms-win-core-wow64-l1-1-1.dll GetSystemWow64DirectoryA
GetSystemWow64Directory2W
IsWow64Process2
GetSystemWow64DirectoryW
api-ms-win-core-wow64-l1-1-0.dll Wow64DisableWow64FsRedirection
IsWow64Process
Wow64RevertWow64FsRedirection
api-ms-win-core-wow64-l1-1-3.dll Wow64GetThreadContext
Wow64SetThreadContext
Wow64SuspendThread
api-ms-win-core-systemtopology-l1-1-1.dll GetNumaProximityNodeEx
api-ms-win-core-systemtopology-l1-1-0.dll GetNumaNodeProcessorMaskEx
GetNumaHighestNodeNumber
api-ms-win-core-processtopology-l1-1-0.dll GetProcessGroupAffinity
GetThreadGroupAffinity
SetThreadGroupAffinity
api-ms-win-core-namespace-l1-1-0.dll ClosePrivateNamespace
DeleteBoundaryDescriptor
OpenPrivateNamespaceW
CreatePrivateNamespaceW
CreateBoundaryDescriptorW
AddSIDToBoundaryDescriptor
api-ms-win-core-file-l2-1-2.dll CopyFileW
CreateHardLinkA
api-ms-win-core-file-l2-1-0.dll CopyFileExW
CopyFile2
ReadDirectoryChangesW
ReOpenFile
CreateSymbolicLinkW
CreateHardLinkW
GetFileInformationByHandleEx
CreateDirectoryExW
MoveFileWithProgressW
MoveFileExW
ReplaceFileW
api-ms-win-core-file-l2-1-3.dll ReadDirectoryChangesExW
api-ms-win-core-file-l2-1-1.dll OpenFileById
api-ms-win-core-xstate-l2-1-0.dll LocateXStateFeature
SetXStateFeaturesMask
GetXStateFeaturesMask
InitializeContext
GetEnabledXStateFeatures
CopyContext
api-ms-win-core-xstate-l2-1-1.dll InitializeContext2
api-ms-win-core-localization-l2-1-0.dll EnumTimeFormatsEx
GetCurrencyFormatEx
GetNumberFormatEx
EnumCalendarInfoW
EnumDateFormatsExEx
EnumCalendarInfoExEx
EnumTimeFormatsW
EnumSystemCodePagesW
EnumCalendarInfoExW
EnumDateFormatsW
EnumDateFormatsExW
api-ms-win-core-normalization-l1-1-0.dll VerifyScripts
NormalizeString
IdnToNameprepUnicode
GetStringScripts
IsNormalizedString
api-ms-win-core-fibers-l2-1-0.dll CreateFiber
SwitchToFiber
DeleteFiber
ConvertThreadToFiber
ConvertFiberToThread
api-ms-win-core-fibers-l2-1-1.dll ConvertThreadToFiberEx
CreateFiberEx
api-ms-win-core-localization-private-l1-1-0.dll NlsCheckPolicy
NlsUpdateSystemLocale
NlsGetCacheUpdateCount
NlsUpdateLocale
api-ms-win-core-sidebyside-l1-1-0.dll QueryActCtxSettingsW
QueryActCtxW
GetCurrentActCtx
FindActCtxSectionStringW
FindActCtxSectionGuid
DeactivateActCtx
CreateActCtxW
ZombifyActCtx
AddRefActCtx
ActivateActCtx
ReleaseActCtx
api-ms-win-core-appcompat-l1-1-0.dll BaseUpdateAppcompatCache
BaseFlushAppcompatCache
BaseDumpAppcompatCache
BaseInitAppcompatCacheSupport
BaseCleanupAppcompatCacheSupport
BaseCheckAppcompatCacheEx
BaseCheckAppcompatCache
api-ms-win-core-windowserrorreporting-l1-1-0.dll WerUnregisterMemoryBlock
WerRegisterMemoryBlock
GetApplicationRestartSettings
WerRegisterFile
WerUnregisterFile
WerRegisterRuntimeExceptionModule
WerUnregisterRuntimeExceptionModule
GetApplicationRecoveryCallback
api-ms-win-core-windowserrorreporting-l1-1-3.dll RegisterApplicationRestart
UnregisterApplicationRestart
api-ms-win-core-windowserrorreporting-l1-1-1.dll WerUnregisterExcludedMemoryBlock
WerRegisterAdditionalProcess
WerUnregisterCustomMetadata
WerRegisterCustomMetadata
WerRegisterExcludedMemoryBlock
WerUnregisterAdditionalProcess
api-ms-win-core-windowserrorreporting-l1-1-2.dll WerRegisterAppLocalDump
WerUnregisterAppLocalDump
api-ms-win-core-console-l1-1-0.dll AllocConsole
GetConsoleCP
GetConsoleMode
GetConsoleOutputCP
GetNumberOfConsoleInputEvents
ReadConsoleA
ReadConsoleInputA
ReadConsoleInputW
ReadConsoleW
SetConsoleCtrlHandler
SetConsoleMode
WriteConsoleA
WriteConsoleW
api-ms-win-core-console-l1-2-0.dll FreeConsole
PeekConsoleInputA
PeekConsoleInputW
AttachConsole
api-ms-win-core-console-l1-2-1.dll CreatePseudoConsole
ClosePseudoConsole
ResizePseudoConsole
api-ms-win-core-console-l2-1-0.dll SetConsoleWindowInfo
FlushConsoleInputBuffer
GetConsoleScreenBufferInfo
GetConsoleScreenBufferInfoEx
FillConsoleOutputCharacterW
GenerateConsoleCtrlEvent
GetConsoleCursorInfo
SetConsoleScreenBufferSize
SetConsoleScreenBufferInfoEx
GetLargestConsoleWindowSize
ReadConsoleOutputA
CreateConsoleScreenBuffer
FillConsoleOutputAttribute
ReadConsoleOutputCharacterA
SetConsoleTextAttribute
ReadConsoleOutputAttribute
ReadConsoleOutputCharacterW
ReadConsoleOutputW
ScrollConsoleScreenBufferA
ScrollConsoleScreenBufferW
SetConsoleActiveScreenBuffer
SetConsoleCP
SetConsoleCursorInfo
SetConsoleCursorPosition
WriteConsoleInputA
WriteConsoleInputW
WriteConsoleOutputA
WriteConsoleOutputAttribute
WriteConsoleOutputCharacterA
FillConsoleOutputCharacterA
WriteConsoleOutputCharacterW
WriteConsoleOutputW
SetConsoleOutputCP
api-ms-win-core-console-l2-2-0.dll GetConsoleTitleA
GetConsoleOriginalTitleW
SetConsoleTitleA
SetConsoleTitleW
GetConsoleOriginalTitleA
GetConsoleTitleW
api-ms-win-core-console-l3-2-0.dll GetConsoleAliasExesA
GetConsoleAliasExesLengthW
GetConsoleAliasA
ExpungeConsoleCommandHistoryW
GetConsoleAliasExesW
ExpungeConsoleCommandHistoryA
AddConsoleAliasW
AddConsoleAliasA
GetConsoleAliasExesLengthA
GetConsoleAliasW
SetCurrentConsoleFontEx
SetConsoleNumberOfCommandsW
SetConsoleNumberOfCommandsA
SetConsoleHistoryInfo
SetConsoleDisplayMode
GetNumberOfConsoleMouseButtons
GetCurrentConsoleFontEx
GetCurrentConsoleFont
GetConsoleWindow
GetConsoleSelectionInfo
GetConsoleProcessList
GetConsoleHistoryInfo
GetConsoleFontSize
GetConsoleDisplayMode
GetConsoleCommandHistoryW
GetConsoleCommandHistoryLengthW
GetConsoleCommandHistoryLengthA
GetConsoleCommandHistoryA
GetConsoleAliasesW
GetConsoleAliasesLengthW
GetConsoleAliasesLengthA
GetConsoleAliasesA
api-ms-win-core-psapi-l1-1-0.dll K32GetModuleBaseNameW
K32EnumProcessModulesEx
K32EnumPageFilesW
K32GetPerformanceInfo
K32EnumProcesses
K32GetProcessMemoryInfo
K32GetModuleFileNameExW
K32EnumProcessModules
K32GetProcessImageFileNameW
K32GetModuleInformation
K32GetDeviceDriverFileNameW
K32GetDeviceDriverBaseNameW
K32EnumDeviceDrivers
K32GetMappedFileNameW
K32GetWsChangesEx
QueryFullProcessImageNameW
K32EmptyWorkingSet
K32QueryWorkingSet
K32GetWsChanges
K32InitializeProcessForWsWatch
K32QueryWorkingSetEx
api-ms-win-core-psapi-ansi-l1-1-0.dll K32EnumPageFilesA
K32GetDeviceDriverFileNameA
K32GetDeviceDriverBaseNameA
K32GetMappedFileNameA
K32GetModuleFileNameExA
K32GetProcessImageFileNameA
QueryFullProcessImageNameA
K32GetModuleBaseNameA
api-ms-win-eventing-provider-l1-1-0.dll EventRegister
EventWriteTransfer
EventSetInformation
EventUnregister
api-ms-win-core-apiquery-l1-1-0.dll ApiSetQueryApiSetPresence
api-ms-win-core-delayload-l1-1-1.dll ResolveDelayLoadedAPI
api-ms-win-core-appcompat-l1-1-1.dll BaseReadAppCompatDataForProcess
BaseFreeAppCompatDataForProcess
ext-ms-win-oobe-query-l1-1-0.dll (delay-loaded) QueryOOBESupport

Delayed Imports

Attributes 0x1
Name ext-ms-win-oobe-query-l1-1-0.dll
ModuleHandle 0xb29d0
DelayImportAddressTable 0xba058
DelayImportNameTable 0x98d80
BoundDelayImportTable 0x98ea0
UnloadDelayImportTable 0
TimeStamp 1970-Jan-01 00:00:00

AcquireSRWLockExclusive

Ordinal 1
Address 0x9cf13
ForwardName NTDLL.RtlAcquireSRWLockExclusive

AcquireSRWLockShared

Ordinal 2
Address 0x9cf49
ForwardName NTDLL.RtlAcquireSRWLockShared

ActivateActCtx

Ordinal 3
Address 0x20020

ActivateActCtxWorker

Ordinal 4
Address 0x1b6a0

AddAtomA

Ordinal 5
Address 0x591b0

AddAtomW

Ordinal 6
Address 0x12890

AddConsoleAliasA

Ordinal 7
Address 0x255e0

AddConsoleAliasW

Ordinal 8
Address 0x255f0

AddDllDirectory

Ordinal 9
Address 0x9cfcf
ForwardName api-ms-win-core-libraryloader-l1-1-0.AddDllDirectory

AddIntegrityLabelToBoundaryDescriptor

Ordinal 10
Address 0x3bd50

AddLocalAlternateComputerNameA

Ordinal 11
Address 0x592f0

AddLocalAlternateComputerNameW

Ordinal 12
Address 0x59350

AddRefActCtx

Ordinal 13
Address 0x22210

AddRefActCtxWorker

Ordinal 14
Address 0x1e260

AddResourceAttributeAce

Ordinal 15
Address 0x39690

AddSIDToBoundaryDescriptor

Ordinal 16
Address 0x20840

AddScopedPolicyIDAce

Ordinal 17
Address 0x396b0

AddSecureMemoryCacheCallback

Ordinal 18
Address 0x37ab0

AddVectoredContinueHandler

Ordinal 19
Address 0x9d108
ForwardName NTDLL.RtlAddVectoredContinueHandler

AddVectoredExceptionHandler

Ordinal 20
Address 0x9d148
ForwardName NTDLL.RtlAddVectoredExceptionHandler

AdjustCalendarDate

Ordinal 21
Address 0x7200

AllocConsole

Ordinal 22
Address 0x25230

AllocateUserPhysicalPages

Ordinal 23
Address 0x396f0

AllocateUserPhysicalPagesNuma

Ordinal 24
Address 0x396d0

AppPolicyGetClrCompat

Ordinal 25
Address 0x9d1db
ForwardName kernelbase.AppPolicyGetClrCompat

AppPolicyGetCreateFileAccess

Ordinal 26
Address 0x9d219
ForwardName kernelbase.AppPolicyGetCreateFileAccess

AppPolicyGetLifecycleManagement

Ordinal 27
Address 0x9d261
ForwardName kernelbase.AppPolicyGetLifecycleManagement

AppPolicyGetMediaFoundationCodecLoading

Ordinal 28
Address 0x9d2b4
ForwardName kernelbase.AppPolicyGetMediaFoundationCodecLoading

AppPolicyGetProcessTerminationMethod

Ordinal 29
Address 0x9d30c
ForwardName kernelbase.AppPolicyGetProcessTerminationMethod

AppPolicyGetShowDeveloperDiagnostic

Ordinal 30
Address 0x9d360
ForwardName kernelbase.AppPolicyGetShowDeveloperDiagnostic

AppPolicyGetThreadInitializationType

Ordinal 31
Address 0x9d3b4
ForwardName kernelbase.AppPolicyGetThreadInitializationType

AppPolicyGetWindowingModel

Ordinal 32
Address 0x9d3ff
ForwardName kernelbase.AppPolicyGetWindowingModel

AppXGetOSMaxVersionTested

Ordinal 33
Address 0x9d43f
ForwardName kernelbase.AppXGetOSMaxVersionTested

ApplicationRecoveryFinished

Ordinal 34
Address 0x42ea0

ApplicationRecoveryInProgress

Ordinal 35
Address 0x42eb0

AreFileApisANSI

Ordinal 36
Address 0x20b90

AssignProcessToJobObject

Ordinal 37
Address 0x1fea0

AttachConsole

Ordinal 38
Address 0x25240

BackupRead

Ordinal 39
Address 0x5bd60

BackupSeek

Ordinal 40
Address 0x5cea0

BackupWrite

Ordinal 41
Address 0x5d180

BaseCheckAppcompatCache

Ordinal 42
Address 0x39770

BaseCheckAppcompatCacheEx

Ordinal 43
Address 0x39710

BaseCheckAppcompatCacheExWorker

Ordinal 44
Address 0x20f00

BaseCheckAppcompatCacheWorker

Ordinal 45
Address 0x20f00

BaseCheckElevation

Ordinal 46
Address 0x186f0

BaseCleanupAppcompatCacheSupport

Ordinal 47
Address 0x39790

BaseCleanupAppcompatCacheSupportWorker

Ordinal 48
Address 0x21380

BaseDestroyVDMEnvironment

Ordinal 49
Address 0x3f6a0

BaseDllReadWriteIniFile

Ordinal 50
Address 0xc500

BaseDumpAppcompatCache

Ordinal 51
Address 0x397b0

BaseDumpAppcompatCacheWorker

Ordinal 52
Address 0x36bd0

BaseElevationPostProcessing

Ordinal 53
Address 0x1d2b0

BaseFlushAppcompatCache

Ordinal 54
Address 0x397d0

BaseFlushAppcompatCacheWorker

Ordinal 55
Address 0x6f950

BaseFormatObjectAttributes

Ordinal 56
Address 0x24800

BaseFormatTimeOut

Ordinal 57
Address 0x589d0

BaseFreeAppCompatDataForProcessWorker

Ordinal 58
Address 0x1fe00

BaseGenerateAppCompatData

Ordinal 59
Address 0x16750

BaseGetNamedObjectDirectory

Ordinal 60
Address 0x397f0

BaseInitAppcompatCacheSupport

Ordinal 61
Address 0x39810

BaseInitAppcompatCacheSupportWorker

Ordinal 62
Address 0x21380

BaseIsAppcompatInfrastructureDisabled

Ordinal 63
Address 0x20f00

BaseIsAppcompatInfrastructureDisabledWorker

Ordinal 64
Address 0x20f00

BaseIsDosApplication

Ordinal 65
Address 0x5fcd0

BaseQueryModuleData

Ordinal 66
Address 0x6fdc0

BaseReadAppCompatDataForProcessWorker

Ordinal 67
Address 0x1f690

BaseSetLastNTError

Ordinal 68
Address 0x13080

BaseThreadInitThunk

Ordinal 69
Address 0x16fc0

BaseUpdateAppcompatCache

Ordinal 70
Address 0x39830

BaseUpdateAppcompatCacheWorker

Ordinal 71
Address 0x6f9b0

BaseUpdateVDMEntry

Ordinal 72
Address 0x3fa00

BaseVerifyUnicodeString

Ordinal 73
Address 0x58a70

BaseWriteErrorElevationRequiredEvent

Ordinal 74
Address 0x5e4a0

Basep8BitStringToDynamicUnicodeString

Ordinal 75
Address 0x1c030

BasepAllocateActivationContextActivationBlock

Ordinal 76
Address 0x58ad0

BasepAnsiStringToDynamicUnicodeString

Ordinal 77
Address 0x58a00

BasepAppContainerEnvironmentExtension

Ordinal 78
Address 0x7600

BasepAppXExtension

Ordinal 79
Address 0x20340

BasepCheckAppCompat

Ordinal 80
Address 0x18ca0

BasepCheckWebBladeHashes

Ordinal 81
Address 0x1cfb0

BasepCheckWinSaferRestrictions

Ordinal 82
Address 0x11d90

BasepConstructSxsCreateProcessMessage

Ordinal 83
Address 0xdce0

BasepCopyEncryption

Ordinal 84
Address 0x37560

BasepFinishPackageActivationForSxS

Ordinal 85
Address 0x25a90

BasepFreeActivationContextActivationBlock

Ordinal 86
Address 0x58c60

BasepFreeAppCompatData

Ordinal 87
Address 0x1bb30

BasepGetAppCompatData

Ordinal 88
Address 0x15db0

BasepGetComputerNameFromNtPath

Ordinal 89
Address 0x1a0f0

BasepGetExeArchType

Ordinal 90
Address 0x19480

BasepGetPackageActivationTokenForSxS

Ordinal 91
Address 0x25ad0

BasepInitAppCompatData

Ordinal 92
Address 0x6fae0

BasepIsProcessAllowed

Ordinal 93
Address 0x1c160

BasepMapModuleHandle

Ordinal 94
Address 0x136e0

BasepNotifyLoadStringResource

Ordinal 95
Address 0x1b5b0

BasepPostSuccessAppXExtension

Ordinal 96
Address 0x20b50

BasepProcessInvalidImage

Ordinal 97
Address 0x38700

BasepQueryAppCompat

Ordinal 98
Address 0xcee0

BasepQueryModuleChpeSettings

Ordinal 99
Address 0x6fb70

BasepReleaseAppXContext

Ordinal 100
Address 0x20b30

BasepReleaseSxsCreateProcessUtilityStruct

Ordinal 101
Address 0x14b30

BasepReportFault

Ordinal 102
Address 0x43160

BasepSetFileEncryptionCompression

Ordinal 103
Address 0x1e350

Beep

Ordinal 104
Address 0x36900

BeginUpdateResourceA

Ordinal 105
Address 0x48ca0

BeginUpdateResourceW

Ordinal 106
Address 0x48d10

BindIoCompletionCallback

Ordinal 107
Address 0x24200

BuildCommDCBA

Ordinal 108
Address 0x41650

BuildCommDCBAndTimeoutsA

Ordinal 109
Address 0x416b0

BuildCommDCBAndTimeoutsW

Ordinal 110
Address 0x416f0

BuildCommDCBW

Ordinal 111
Address 0x41780

CallNamedPipeA

Ordinal 112
Address 0x60520

CallNamedPipeW

Ordinal 113
Address 0x24fd0

CallbackMayRunLong

Ordinal 114
Address 0x39850

CancelDeviceWakeupRequest

Ordinal 115
Address 0x38650

CancelIo

Ordinal 116
Address 0x20c10

CancelIoEx

Ordinal 117
Address 0x1ffe0

CancelSynchronousIo

Ordinal 118
Address 0x39890

CancelThreadpoolIo

Ordinal 119
Address 0x9dcf9
ForwardName NTDLL.TpCancelAsyncIoOperation

CancelTimerQueueTimer

Ordinal 120
Address 0x430c0

CancelWaitableTimer

Ordinal 121
Address 0x248c0

CeipIsOptedIn

Ordinal 122
Address 0x9dd50
ForwardName kernelbase.CeipIsOptedIn

ChangeTimerQueueTimer

Ordinal 123
Address 0x21220

CheckAllowDecryptedRemoteDestinationPolicy

Ordinal 124
Address 0x398b0

CheckElevation

Ordinal 125
Address 0x185b0

CheckElevationEnabled

Ordinal 126
Address 0x20590

CheckForReadOnlyResource

Ordinal 127
Address 0x60a20

CheckForReadOnlyResourceFilter

Ordinal 128
Address 0x3bd80

CheckNameLegalDOS8Dot3A

Ordinal 129
Address 0x38460

CheckNameLegalDOS8Dot3W

Ordinal 130
Address 0x38510

CheckRemoteDebuggerPresent

Ordinal 131
Address 0x1250

CheckTokenCapability

Ordinal 132
Address 0x398d0

CheckTokenMembershipEx

Ordinal 133
Address 0x398f0

ClearCommBreak

Ordinal 134
Address 0x25030

ClearCommError

Ordinal 135
Address 0x25040

CloseConsoleHandle

Ordinal 136
Address 0x688c0

CloseHandle

Ordinal 137
Address 0x24880

ClosePackageInfo

Ordinal 138
Address 0x9decc
ForwardName kernelbase.ClosePackageInfo

ClosePrivateNamespace

Ordinal 139
Address 0x221b0

CloseProfileUserMapping

Ordinal 140
Address 0x21380

ClosePseudoConsole

Ordinal 141
Address 0x25250

CloseState

Ordinal 142
Address 0x9df34
ForwardName kernelbase.CloseState

CloseThreadpool

Ordinal 143
Address 0x9df5a
ForwardName NTDLL.TpReleasePool

CloseThreadpoolCleanupGroup

Ordinal 144
Address 0x9df8a
ForwardName NTDLL.TpReleaseCleanupGroup

CloseThreadpoolCleanupGroupMembers

Ordinal 145
Address 0x9dfc9
ForwardName NTDLL.TpReleaseCleanupGroupMembers

CloseThreadpoolIo

Ordinal 146
Address 0x9dffe
ForwardName NTDLL.TpReleaseIoCompletion

CloseThreadpoolTimer

Ordinal 147
Address 0x9e02f
ForwardName NTDLL.TpReleaseTimer

CloseThreadpoolWait

Ordinal 148
Address 0x9e058
ForwardName NTDLL.TpReleaseWait

CloseThreadpoolWork

Ordinal 149
Address 0x9e080
ForwardName NTDLL.TpReleaseWork

CmdBatNotification

Ordinal 150
Address 0x1ff10

CommConfigDialogA

Ordinal 151
Address 0x3cb10

CommConfigDialogW

Ordinal 152
Address 0x3cbc0

CompareCalendarDates

Ordinal 153
Address 0x496b0

CompareFileTime

Ordinal 154
Address 0x24ab0

CompareStringA

Ordinal 155
Address 0x1d5c0

CompareStringEx

Ordinal 156
Address 0x15bf0

CompareStringOrdinal

Ordinal 157
Address 0x15d90

CompareStringW

Ordinal 158
Address 0x1c640

ConnectNamedPipe

Ordinal 159
Address 0x20f70

ConsoleMenuControl

Ordinal 160
Address 0x68a00

ContinueDebugEvent

Ordinal 161
Address 0x39910

ConvertCalDateTimeToSystemTime

Ordinal 162
Address 0x49760

ConvertDefaultLocale

Ordinal 163
Address 0x39930

ConvertFiberToThread

Ordinal 164
Address 0x25180

ConvertNLSDayOfWeekToWin32DayOfWeek

Ordinal 165
Address 0x49860

ConvertSystemTimeToCalDateTime

Ordinal 166
Address 0x74b0

ConvertThreadToFiber

Ordinal 167
Address 0x25190

ConvertThreadToFiberEx

Ordinal 168
Address 0x251a0

CopyContext

Ordinal 169
Address 0x39950

CopyFile2

Ordinal 170
Address 0x39970

CopyFileA

Ordinal 171
Address 0x60d70

CopyFileExA

Ordinal 172
Address 0x60e20

CopyFileExW

Ordinal 173
Address 0x20660

CopyFileTransactedA

Ordinal 174
Address 0x60ee0

CopyFileTransactedW

Ordinal 175
Address 0x60fd0

CopyFileW

Ordinal 176
Address 0x25170

CopyLZFile

Ordinal 177
Address 0x36ac0

CreateActCtxA

Ordinal 178
Address 0x21b60

CreateActCtxW

Ordinal 179
Address 0x21130

CreateActCtxWWorker

Ordinal 180
Address 0x13750

CreateBoundaryDescriptorA

Ordinal 181
Address 0x60be0

CreateBoundaryDescriptorW

Ordinal 182
Address 0x207e0

CreateConsoleScreenBuffer

Ordinal 183
Address 0x25370

CreateDirectoryA

Ordinal 184
Address 0x24ac0

CreateDirectoryExA

Ordinal 185
Address 0x61a00

CreateDirectoryExW

Ordinal 186
Address 0x39990

CreateDirectoryTransactedA

Ordinal 187
Address 0x36e20

CreateDirectoryTransactedW

Ordinal 188
Address 0x61a90

CreateDirectoryW

Ordinal 189
Address 0x24ad0

CreateEnclave

Ordinal 190
Address 0x9e3a1
ForwardName api-ms-win-core-enclave-l1-1-0.CreateEnclave

CreateEventA

Ordinal 191
Address 0x248d0

CreateEventExA

Ordinal 192
Address 0x248e0

CreateEventExW

Ordinal 193
Address 0x248f0

CreateEventW

Ordinal 194
Address 0x24900

CreateFiber

Ordinal 195
Address 0x251b0

CreateFiberEx

Ordinal 196
Address 0x251c0

CreateFile2

Ordinal 197
Address 0x24ae0

CreateFileA

Ordinal 198
Address 0x24af0

CreateFileMappingA

Ordinal 199
Address 0x1bc50

CreateFileMappingFromApp

Ordinal 200
Address 0x9e464
ForwardName api-ms-win-core-memory-l1-1-1.CreateFileMappingFromApp

CreateFileMappingNumaA

Ordinal 201
Address 0x61c40

CreateFileMappingNumaW

Ordinal 202
Address 0x399b0

CreateFileMappingW

Ordinal 203
Address 0x1c880

CreateFileTransactedA

Ordinal 204
Address 0x610d0

CreateFileTransactedW

Ordinal 205
Address 0x61190

CreateFileW

Ordinal 206
Address 0x24b00

CreateHardLinkA

Ordinal 207
Address 0x399d0

CreateHardLinkTransactedA

Ordinal 208
Address 0x42880

CreateHardLinkTransactedW

Ordinal 209
Address 0x61d10

CreateHardLinkW

Ordinal 210
Address 0x399f0

CreateIoCompletionPort

Ordinal 211
Address 0x1d8f0

CreateJobObjectA

Ordinal 212
Address 0x5b2e0

CreateJobObjectW

Ordinal 213
Address 0x1e190

CreateJobSet

Ordinal 214
Address 0x5b350

CreateMailslotA

Ordinal 215
Address 0x1be00

CreateMailslotW

Ordinal 216
Address 0x1be70

CreateMemoryResourceNotification

Ordinal 217
Address 0x20880

CreateMutexA

Ordinal 218
Address 0x24910

CreateMutexExA

Ordinal 219
Address 0x24920

CreateMutexExW

Ordinal 220
Address 0x24930

CreateMutexW

Ordinal 221
Address 0x24940

CreateNamedPipeA

Ordinal 222
Address 0x605c0

CreateNamedPipeW

Ordinal 223
Address 0x20210

CreatePipe

Ordinal 224
Address 0x201f0

CreatePrivateNamespaceA

Ordinal 225
Address 0x60c50

CreatePrivateNamespaceW

Ordinal 226
Address 0x207a0

CreateProcessA

Ordinal 227
Address 0x1c700

CreateProcessAsUserA

Ordinal 228
Address 0x39a10

CreateProcessAsUserW

Ordinal 229
Address 0x1da60

CreateProcessInternalA

Ordinal 230
Address 0x39a90

CreateProcessInternalW

Ordinal 231
Address 0x39b10

CreateProcessW

Ordinal 232
Address 0x1cb00

CreatePseudoConsole

Ordinal 233
Address 0x25260

CreateRemoteThread

Ordinal 234
Address 0x39b90

CreateRemoteThreadEx

Ordinal 235
Address 0x9e736
ForwardName api-ms-win-core-processthreads-l1-1-0.CreateRemoteThreadEx

CreateSemaphoreA

Ordinal 236
Address 0x1bd20

CreateSemaphoreExA

Ordinal 237
Address 0x1bd50

CreateSemaphoreExW

Ordinal 238
Address 0x24950

CreateSemaphoreW

Ordinal 239
Address 0x24960

CreateSymbolicLinkA

Ordinal 240
Address 0x622e0

CreateSymbolicLinkTransactedA

Ordinal 241
Address 0x623a0

CreateSymbolicLinkTransactedW

Ordinal 242
Address 0x62460

CreateSymbolicLinkW

Ordinal 243
Address 0x39be0

CreateTapePartition

Ordinal 244
Address 0x425c0

CreateThread

Ordinal 245
Address 0x1b540

CreateThreadpool

Ordinal 246
Address 0x20bd0

CreateThreadpoolCleanupGroup

Ordinal 247
Address 0x21150

CreateThreadpoolIo

Ordinal 248
Address 0x20d00

CreateThreadpoolTimer

Ordinal 249
Address 0x1c600

CreateThreadpoolWait

Ordinal 250
Address 0x20740

CreateThreadpoolWork

Ordinal 251
Address 0x20550

CreateTimerQueue

Ordinal 252
Address 0x211e0

CreateTimerQueueTimer

Ordinal 253
Address 0x1e240

CreateToolhelp32Snapshot

Ordinal 254
Address 0x263f0

CreateUmsCompletionList

Ordinal 255
Address 0x411d0

CreateUmsThreadContext

Ordinal 256
Address 0x41210

CreateWaitableTimerA

Ordinal 257
Address 0x61f60

CreateWaitableTimerExA

Ordinal 258
Address 0x61f80

CreateWaitableTimerExW

Ordinal 259
Address 0x24970

CreateWaitableTimerW

Ordinal 260
Address 0x10b0

CtrlRoutine

Ordinal 261
Address 0x9e992
ForwardName kernelbase.CtrlRoutine

DeactivateActCtx

Ordinal 262
Address 0x20040

DeactivateActCtxWorker

Ordinal 263
Address 0x1b7f0

DebugActiveProcess

Ordinal 264
Address 0x39c20

DebugActiveProcessStop

Ordinal 265
Address 0x39c00

DebugBreak

Ordinal 266
Address 0x39c40

DebugBreakProcess

Ordinal 267
Address 0x36d10

DebugSetProcessKillOnExit

Ordinal 268
Address 0x36d40

DecodePointer

Ordinal 269
Address 0x9ea40
ForwardName NTDLL.RtlDecodePointer

DecodeSystemPointer

Ordinal 270
Address 0x9ea6b
ForwardName NTDLL.RtlDecodeSystemPointer

DefineDosDeviceA

Ordinal 271
Address 0x63c10

DefineDosDeviceW

Ordinal 272
Address 0x24b10

DelayLoadFailureHook

Ordinal 273
Address 0x242b0

DeleteAtom

Ordinal 274
Address 0x12800

DeleteBoundaryDescriptor

Ordinal 275
Address 0x207c0

DeleteCriticalSection

Ordinal 276
Address 0x9eaf9
ForwardName NTDLL.RtlDeleteCriticalSection

DeleteFiber

Ordinal 277
Address 0x251d0

DeleteFileA

Ordinal 278
Address 0x24b20

DeleteFileTransactedA

Ordinal 279
Address 0x62540

DeleteFileTransactedW

Ordinal 280
Address 0x24110

DeleteFileW

Ordinal 281
Address 0x24b30

DeleteProcThreadAttributeList

Ordinal 282
Address 0x9eb86
ForwardName api-ms-win-core-processthreads-l1-1-0.DeleteProcThreadAttributeList

DeleteSynchronizationBarrier

Ordinal 283
Address 0x39c60

DeleteTimerQueue

Ordinal 284
Address 0x21190

DeleteTimerQueueEx

Ordinal 285
Address 0x21200

DeleteTimerQueueTimer

Ordinal 286
Address 0x203c0

DeleteUmsCompletionList

Ordinal 287
Address 0x41250

DeleteUmsThreadContext

Ordinal 288
Address 0x41290

DeleteVolumeMountPointA

Ordinal 289
Address 0x63eb0

DeleteVolumeMountPointW

Ordinal 290
Address 0x24b40

DequeueUmsCompletionListItems

Ordinal 291
Address 0x412d0

DeviceIoControl

Ordinal 292
Address 0x15530

DisableThreadLibraryCalls

Ordinal 293
Address 0x1fe60

DisableThreadProfiling

Ordinal 294
Address 0x431a0

DisassociateCurrentThreadFromCallback

Ordinal 295
Address 0x9ed05
ForwardName NTDLL.TpDisassociateCallback

DiscardVirtualMemory

Ordinal 296
Address 0x9ed37
ForwardName api-ms-win-core-memory-l1-1-2.DiscardVirtualMemory

DisconnectNamedPipe

Ordinal 297
Address 0x21f00

DnsHostnameToComputerNameA

Ordinal 298
Address 0x5a280

DnsHostnameToComputerNameExW

Ordinal 299
Address 0x39c80

DnsHostnameToComputerNameW

Ordinal 300
Address 0x1c4b0

DosDateTimeToFileTime

Ordinal 301
Address 0x12a30

DosPathToSessionPathA

Ordinal 302
Address 0x652b0

DosPathToSessionPathW

Ordinal 303
Address 0x654b0

DuplicateConsoleHandle

Ordinal 304
Address 0x688e0

DuplicateEncryptionInfoFileExt

Ordinal 305
Address 0x378b0

DuplicateHandle

Ordinal 306
Address 0x24890

EnableThreadProfiling

Ordinal 307
Address 0x431e0

EncodePointer

Ordinal 308
Address 0x9ee7d
ForwardName NTDLL.RtlEncodePointer

EncodeSystemPointer

Ordinal 309
Address 0x9eea8
ForwardName NTDLL.RtlEncodeSystemPointer

EndUpdateResourceA

Ordinal 310
Address 0x48f60

EndUpdateResourceW

Ordinal 311
Address 0x48f70

EnterCriticalSection

Ordinal 312
Address 0x9ef00
ForwardName NTDLL.RtlEnterCriticalSection

EnterSynchronizationBarrier

Ordinal 313
Address 0x39ca0

EnterUmsSchedulingMode

Ordinal 314
Address 0x41330

EnumCalendarInfoA

Ordinal 315
Address 0x4a350

EnumCalendarInfoExA

Ordinal 316
Address 0x4a3f0

EnumCalendarInfoExEx

Ordinal 317
Address 0x1c6e0

EnumCalendarInfoExW

Ordinal 318
Address 0x39cc0

EnumCalendarInfoW

Ordinal 319
Address 0x39ce0

EnumDateFormatsA

Ordinal 320
Address 0x4a490

EnumDateFormatsExA

Ordinal 321
Address 0x4a4f0

EnumDateFormatsExEx

Ordinal 322
Address 0x39d00

EnumDateFormatsExW

Ordinal 323
Address 0x39d20

EnumDateFormatsW

Ordinal 324
Address 0x39d40

EnumLanguageGroupLocalesA

Ordinal 325
Address 0x4a560

EnumLanguageGroupLocalesW

Ordinal 326
Address 0x39d60

EnumResourceLanguagesA

Ordinal 327
Address 0x37d00

EnumResourceLanguagesExA

Ordinal 328
Address 0x39d80

EnumResourceLanguagesExW

Ordinal 329
Address 0x39da0

EnumResourceLanguagesW

Ordinal 330
Address 0x37d40

EnumResourceNamesA

Ordinal 331
Address 0x37d80

EnumResourceNamesExA

Ordinal 332
Address 0x39dc0

EnumResourceNamesExW

Ordinal 333
Address 0x39de0

EnumResourceNamesW

Ordinal 334
Address 0x24fb0

EnumResourceTypesA

Ordinal 335
Address 0x37db0

EnumResourceTypesExA

Ordinal 336
Address 0x39e00

EnumResourceTypesExW

Ordinal 337
Address 0x39e20

EnumResourceTypesW

Ordinal 338
Address 0x37de0

EnumSystemCodePagesA

Ordinal 339
Address 0x4a590

EnumSystemCodePagesW

Ordinal 340
Address 0x39e40

EnumSystemFirmwareTables

Ordinal 341
Address 0x37ae0

EnumSystemGeoID

Ordinal 342
Address 0x53590

EnumSystemGeoNames

Ordinal 343
Address 0x53680

EnumSystemLanguageGroupsA

Ordinal 344
Address 0x4a5b0

EnumSystemLanguageGroupsW

Ordinal 345
Address 0x39e60

EnumSystemLocalesA

Ordinal 346
Address 0x39e80

EnumSystemLocalesEx

Ordinal 347
Address 0x39ea0

EnumSystemLocalesW

Ordinal 348
Address 0x39ec0

EnumTimeFormatsA

Ordinal 349
Address 0x4a5d0

EnumTimeFormatsEx

Ordinal 350
Address 0x203e0

EnumTimeFormatsW

Ordinal 351
Address 0x39ee0

EnumUILanguagesA

Ordinal 352
Address 0x4a650

EnumUILanguagesW

Ordinal 353
Address 0x39f00

EnumerateLocalComputerNamesA

Ordinal 354
Address 0x5a370

EnumerateLocalComputerNamesW

Ordinal 355
Address 0x5a4a0

EraseTape

Ordinal 356
Address 0x42620

EscapeCommFunction

Ordinal 357
Address 0x25050

ExecuteUmsThread

Ordinal 358
Address 0x413e0

ExitProcess

Ordinal 359
Address 0x1e040

ExitThread

Ordinal 360
Address 0x9f2eb
ForwardName NTDLL.RtlExitUserThread

ExitVDM

Ordinal 361
Address 0x3fca0

ExpandEnvironmentStringsA

Ordinal 362
Address 0x221f0

ExpandEnvironmentStringsW

Ordinal 363
Address 0x1b730

ExpungeConsoleCommandHistoryA

Ordinal 364
Address 0x25600

ExpungeConsoleCommandHistoryW

Ordinal 365
Address 0x25610

FatalAppExitA

Ordinal 366
Address 0x39f20

FatalAppExitW

Ordinal 367
Address 0x39f40

FatalExit

Ordinal 368
Address 0x1e040

FileTimeToDosDateTime

Ordinal 369
Address 0x12cd0

FileTimeToLocalFileTime

Ordinal 370
Address 0x24b50

FileTimeToSystemTime

Ordinal 371
Address 0x24ff0

FillConsoleOutputAttribute

Ordinal 372
Address 0x25380

FillConsoleOutputCharacterA

Ordinal 373
Address 0x25390

FillConsoleOutputCharacterW

Ordinal 374
Address 0x253a0

FindActCtxSectionGuid

Ordinal 375
Address 0x1bc30

FindActCtxSectionGuidWorker

Ordinal 376
Address 0x12f30

FindActCtxSectionStringA

Ordinal 377
Address 0x65640

FindActCtxSectionStringW

Ordinal 378
Address 0x210a0

FindActCtxSectionStringWWorker

Ordinal 379
Address 0x13250

FindAtomA

Ordinal 380
Address 0x151e0

FindAtomW

Ordinal 381
Address 0x12cb0

FindClose

Ordinal 382
Address 0x24b60

FindCloseChangeNotification

Ordinal 383
Address 0x24b70

FindFirstChangeNotificationA

Ordinal 384
Address 0x24b80

FindFirstChangeNotificationW

Ordinal 385
Address 0x24b90

FindFirstFileA

Ordinal 386
Address 0x24ba0

FindFirstFileExA

Ordinal 387
Address 0x24bb0

FindFirstFileExW

Ordinal 388
Address 0x24bc0

FindFirstFileNameTransactedW

Ordinal 389
Address 0x36f20

FindFirstFileNameW

Ordinal 390
Address 0x24bd0

FindFirstFileTransactedA

Ordinal 391
Address 0x37000

FindFirstFileTransactedW

Ordinal 392
Address 0x656e0

FindFirstFileW

Ordinal 393
Address 0x24be0

FindFirstStreamTransactedW

Ordinal 394
Address 0x370f0

FindFirstStreamW

Ordinal 395
Address 0x9f5fc
ForwardName api-ms-win-core-file-l1-2-2.FindFirstStreamW

FindFirstVolumeA

Ordinal 396
Address 0x63f00

FindFirstVolumeMountPointA

Ordinal 397
Address 0x640a0

FindFirstVolumeMountPointW

Ordinal 398
Address 0x64290

FindFirstVolumeW

Ordinal 399
Address 0x24bf0

FindNLSString

Ordinal 400
Address 0x39f60

FindNLSStringEx

Ordinal 401
Address 0x157d0

FindNextChangeNotification

Ordinal 402
Address 0x24c00

FindNextFileA

Ordinal 403
Address 0x24c10

FindNextFileNameW

Ordinal 404
Address 0x24c20

FindNextFileW

Ordinal 405
Address 0x24c30

FindNextStreamW

Ordinal 406
Address 0x9f6f8
ForwardName api-ms-win-core-file-l1-2-2.FindNextStreamW

FindNextVolumeA

Ordinal 407
Address 0x64520

FindNextVolumeMountPointA

Ordinal 408
Address 0x646c0

FindNextVolumeMountPointW

Ordinal 409
Address 0x64db0

FindNextVolumeW

Ordinal 410
Address 0x24c40

FindPackagesByPackageFamily

Ordinal 411
Address 0x9f794
ForwardName kernelbase.FindPackagesByPackageFamily

FindResourceA

Ordinal 412
Address 0x134d0

FindResourceExA

Ordinal 413
Address 0x134f0

FindResourceExW

Ordinal 414
Address 0x1b320

FindResourceW

Ordinal 415
Address 0x201d0

FindStringOrdinal

Ordinal 416
Address 0x39f80

FindVolumeClose

Ordinal 417
Address 0x24c50

FindVolumeMountPointClose

Ordinal 418
Address 0x64dc0

FlsAlloc

Ordinal 419
Address 0x20170

FlsFree

Ordinal 420
Address 0x20ab0

FlsGetValue

Ordinal 421
Address 0x18480

FlsSetValue

Ordinal 422
Address 0x1c270

FlushConsoleInputBuffer

Ordinal 423
Address 0x253b0

FlushFileBuffers

Ordinal 424
Address 0x24c60

FlushInstructionCache

Ordinal 425
Address 0x1ae20

FlushProcessWriteBuffers

Ordinal 426
Address 0x9f8b4
ForwardName NTDLL.NtFlushProcessWriteBuffers

FlushViewOfFile

Ordinal 427
Address 0x39fa0

FoldStringA

Ordinal 428
Address 0x4a670

FoldStringW

Ordinal 429
Address 0x39fc0

FormatApplicationUserModelId

Ordinal 430
Address 0x9f91a
ForwardName kernelbase.FormatApplicationUserModelId

FormatMessageA

Ordinal 431
Address 0x22020

FormatMessageW

Ordinal 432
Address 0x1c830

FreeConsole

Ordinal 433
Address 0x25270

FreeEnvironmentStringsA

Ordinal 434
Address 0x1fd40

FreeEnvironmentStringsW

Ordinal 435
Address 0x1f650

FreeLibrary

Ordinal 436
Address 0x1c770

FreeLibraryAndExitThread

Ordinal 437
Address 0x20fd0

FreeLibraryWhenCallbackReturns

Ordinal 438
Address 0x9f9e0
ForwardName NTDLL.TpCallbackUnloadDllOnCompletion

FreeMemoryJobObject

Ordinal 439
Address 0x5b380

FreeResource

Ordinal 440
Address 0x21db0

FreeUserPhysicalPages

Ordinal 441
Address 0x39fe0

GenerateConsoleCtrlEvent

Ordinal 442
Address 0x253c0

GetACP

Ordinal 443
Address 0x1e000

GetActiveProcessorCount

Ordinal 444
Address 0x1d450

GetActiveProcessorGroupCount

Ordinal 445
Address 0x65880

GetAppContainerAce

Ordinal 446
Address 0x3a000

GetAppContainerNamedObjectPath

Ordinal 447
Address 0x3a020

GetApplicationRecoveryCallback

Ordinal 448
Address 0x3a040

GetApplicationRecoveryCallbackWorker

Ordinal 449
Address 0x42ec0

GetApplicationRestartSettings

Ordinal 450
Address 0x3a060

GetApplicationRestartSettingsWorker

Ordinal 451
Address 0x42f80

GetApplicationUserModelId

Ordinal 452
Address 0x9fb64
ForwardName kernelbase.GetApplicationUserModelId

GetAtomNameA

Ordinal 453
Address 0x591d0

GetAtomNameW

Ordinal 454
Address 0x125d0

GetBinaryType

Ordinal 455
Address 0x5fde0

GetBinaryTypeA

Ordinal 456
Address 0x5fde0

GetBinaryTypeW

Ordinal 457
Address 0x5fe30

GetCPInfo

Ordinal 458
Address 0x1e280

GetCPInfoExA

Ordinal 459
Address 0x4a920

GetCPInfoExW

Ordinal 460
Address 0x3a080

GetCachedSigningLevel

Ordinal 461
Address 0x3a0a0

GetCalendarDateFormat

Ordinal 462
Address 0x498a0

GetCalendarDateFormatEx

Ordinal 463
Address 0x86b0

GetCalendarDaysInMonth

Ordinal 464
Address 0x73b0

GetCalendarDifferenceInDays

Ordinal 465
Address 0x49b80

GetCalendarInfoA

Ordinal 466
Address 0x4aa00

GetCalendarInfoEx

Ordinal 467
Address 0x25000

GetCalendarInfoW

Ordinal 468
Address 0x25010

GetCalendarMonthsInYear

Ordinal 469
Address 0x49ce0

GetCalendarSupportedDateRange

Ordinal 470
Address 0x7130

GetCalendarWeekNumber

Ordinal 471
Address 0x49db0

GetComPlusPackageInstallStatus

Ordinal 472
Address 0x42df0

GetCommConfig

Ordinal 473
Address 0x25060

GetCommMask

Ordinal 474
Address 0x25070

GetCommModemStatus

Ordinal 475
Address 0x25080

GetCommProperties

Ordinal 476
Address 0x25090

GetCommState

Ordinal 477
Address 0x250a0

GetCommTimeouts

Ordinal 478
Address 0x250b0

GetCommandLineA

Ordinal 479
Address 0x1fde0

GetCommandLineW

Ordinal 480
Address 0x1f360

GetCompressedFileSizeA

Ordinal 481
Address 0x3a0c0

GetCompressedFileSizeTransactedA

Ordinal 482
Address 0x62590

GetCompressedFileSizeTransactedW

Ordinal 483
Address 0x625f0

GetCompressedFileSizeW

Ordinal 484
Address 0x3a0e0

GetComputerNameA

Ordinal 485
Address 0x1a2a0

GetComputerNameExA

Ordinal 486
Address 0x24230

GetComputerNameExW

Ordinal 487
Address 0x20190

GetComputerNameW

Ordinal 488
Address 0x1a400

GetConsoleAliasA

Ordinal 489
Address 0x25620

GetConsoleAliasExesA

Ordinal 490
Address 0x25630

GetConsoleAliasExesLengthA

Ordinal 491
Address 0x25640

GetConsoleAliasExesLengthW

Ordinal 492
Address 0x25650

GetConsoleAliasExesW

Ordinal 493
Address 0x25660

GetConsoleAliasW

Ordinal 494
Address 0x25670

GetConsoleAliasesA

Ordinal 495
Address 0x25680

GetConsoleAliasesLengthA

Ordinal 496
Address 0x25690

GetConsoleAliasesLengthW

Ordinal 497
Address 0x256a0

GetConsoleAliasesW

Ordinal 498
Address 0x256b0

GetConsoleCP

Ordinal 499
Address 0x25280

GetConsoleCharType

Ordinal 500
Address 0x68f10

GetConsoleCommandHistoryA

Ordinal 501
Address 0x256c0

GetConsoleCommandHistoryLengthA

Ordinal 502
Address 0x256d0

GetConsoleCommandHistoryLengthW

Ordinal 503
Address 0x256e0

GetConsoleCommandHistoryW

Ordinal 504
Address 0x256f0

GetConsoleCursorInfo

Ordinal 505
Address 0x253d0

GetConsoleCursorMode

Ordinal 506
Address 0x68f80

GetConsoleDisplayMode

Ordinal 507
Address 0x25700

GetConsoleFontInfo

Ordinal 508
Address 0x692f0

GetConsoleFontSize

Ordinal 509
Address 0x25710

GetConsoleHardwareState

Ordinal 510
Address 0x68a60

GetConsoleHistoryInfo

Ordinal 511
Address 0x25720

GetConsoleInputExeNameA

Ordinal 512
Address 0xa0057
ForwardName kernelbase.GetConsoleInputExeNameA

GetConsoleInputExeNameW

Ordinal 513
Address 0xa0092
ForwardName kernelbase.GetConsoleInputExeNameW

GetConsoleInputWaitHandle

Ordinal 514
Address 0x68980

GetConsoleKeyboardLayoutNameA

Ordinal 515
Address 0x693a0

GetConsoleKeyboardLayoutNameW

Ordinal 516
Address 0x693c0

GetConsoleMode

Ordinal 517
Address 0x25290

GetConsoleNlsMode

Ordinal 518
Address 0x69000

GetConsoleOriginalTitleA

Ordinal 519
Address 0x253e0

GetConsoleOriginalTitleW

Ordinal 520
Address 0x253f0

GetConsoleOutputCP

Ordinal 521
Address 0x252a0

GetConsoleProcessList

Ordinal 522
Address 0x25730

GetConsoleScreenBufferInfo

Ordinal 523
Address 0x25400

GetConsoleScreenBufferInfoEx

Ordinal 524
Address 0x25410

GetConsoleSelectionInfo

Ordinal 525
Address 0x25740

GetConsoleTitleA

Ordinal 526
Address 0x25420

GetConsoleTitleW

Ordinal 527
Address 0x25430

GetConsoleWindow

Ordinal 528
Address 0x25750

GetCurrencyFormatA

Ordinal 529
Address 0x4ac60

GetCurrencyFormatEx

Ordinal 530
Address 0x3a100

GetCurrencyFormatW

Ordinal 531
Address 0x3a120

GetCurrentActCtx

Ordinal 532
Address 0x21f20

GetCurrentActCtxWorker

Ordinal 533
Address 0x1c680

GetCurrentApplicationUserModelId

Ordinal 534
Address 0xa028d
ForwardName kernelbase.GetCurrentApplicationUserModelId

GetCurrentConsoleFont

Ordinal 535
Address 0x25760

GetCurrentConsoleFontEx

Ordinal 536
Address 0x25770

GetCurrentDirectoryA

Ordinal 537
Address 0x20ff0

GetCurrentDirectoryW

Ordinal 538
Address 0x1fed0

GetCurrentPackageFamilyName

Ordinal 539
Address 0xa032d
ForwardName kernelbase.GetCurrentPackageFamilyName

GetCurrentPackageFullName

Ordinal 540
Address 0xa036e
ForwardName kernelbase.GetCurrentPackageFullName

GetCurrentPackageId

Ordinal 541
Address 0xa03a7
ForwardName kernelbase.GetCurrentPackageId

GetCurrentPackageInfo

Ordinal 542
Address 0xa03dc
ForwardName kernelbase.GetCurrentPackageInfo

GetCurrentPackagePath

Ordinal 543
Address 0xa0413
ForwardName kernelbase.GetCurrentPackagePath

GetCurrentProcess

Ordinal 544
Address 0x24820

GetCurrentProcessId

Ordinal 545
Address 0x24830

GetCurrentProcessorNumber

Ordinal 546
Address 0xa0474
ForwardName NTDLL.RtlGetCurrentProcessorNumber

GetCurrentProcessorNumberEx

Ordinal 547
Address 0xa04b3
ForwardName NTDLL.RtlGetCurrentProcessorNumberEx

GetCurrentThread

Ordinal 548
Address 0x15840

GetCurrentThreadId

Ordinal 549
Address 0x154f0

GetCurrentThreadStackLimits

Ordinal 550
Address 0xa0518
ForwardName api-ms-win-core-processthreads-l1-1-0.GetCurrentThreadStackLimits

GetCurrentUmsThread

Ordinal 551
Address 0x41420

GetDateFormatA

Ordinal 552
Address 0x3a130

GetDateFormatAWorker

Ordinal 553
Address 0x22290

GetDateFormatEx

Ordinal 554
Address 0x3a150

GetDateFormatW

Ordinal 555
Address 0x20640

GetDateFormatWWorker

Ordinal 556
Address 0xa790

GetDefaultCommConfigA

Ordinal 557
Address 0x3ce20

GetDefaultCommConfigW

Ordinal 558
Address 0x3ced0

GetDevicePowerState

Ordinal 559
Address 0x661a0

GetDiskFreeSpaceA

Ordinal 560
Address 0x24c70

GetDiskFreeSpaceExA

Ordinal 561
Address 0x24c80

GetDiskFreeSpaceExW

Ordinal 562
Address 0x24c90

GetDiskFreeSpaceW

Ordinal 563
Address 0x24ca0

GetDiskSpaceInformationA

Ordinal 564
Address 0xa066b
ForwardName api-ms-win-core-file-l1-2-3.GetDiskSpaceInformationA

GetDiskSpaceInformationW

Ordinal 565
Address 0xa06b9
ForwardName api-ms-win-core-file-l1-2-3.GetDiskSpaceInformationW

GetDllDirectoryA

Ordinal 566
Address 0x37e10

GetDllDirectoryW

Ordinal 567
Address 0x21e20

GetDriveTypeA

Ordinal 568
Address 0x24cb0

GetDriveTypeW

Ordinal 569
Address 0x24cc0

GetDurationFormat

Ordinal 570
Address 0x4b920

GetDurationFormatEx

Ordinal 571
Address 0x3a170

GetDynamicTimeZoneInformation

Ordinal 572
Address 0x20ee0

GetEnabledXStateFeatures

Ordinal 573
Address 0x3a190

GetEncryptedFileVersionExt

Ordinal 574
Address 0x379b0

GetEnvironmentStrings

Ordinal 575
Address 0x1fd20

GetEnvironmentStringsA

Ordinal 576
Address 0x25020

GetEnvironmentStringsW

Ordinal 577
Address 0x1f630

GetEnvironmentVariableA

Ordinal 578
Address 0x1e2f0

GetEnvironmentVariableW

Ordinal 579
Address 0x1b5c0

GetEraNameCountedString

Ordinal 580
Address 0x3a1b0

GetErrorMode

Ordinal 581
Address 0x22190

GetExitCodeProcess

Ordinal 582
Address 0x1d000

GetExitCodeThread

Ordinal 583
Address 0x1f960

GetExpandedNameA

Ordinal 584
Address 0x3bf10

GetExpandedNameW

Ordinal 585
Address 0x3c000

GetFileAttributesA

Ordinal 586
Address 0x24cd0

GetFileAttributesExA

Ordinal 587
Address 0x24ce0

GetFileAttributesExW

Ordinal 588
Address 0x24cf0

GetFileAttributesTransactedA

Ordinal 589
Address 0x626c0

GetFileAttributesTransactedW

Ordinal 590
Address 0x62730

GetFileAttributesW

Ordinal 591
Address 0x24d00

GetFileBandwidthReservation

Ordinal 592
Address 0x371d0

GetFileInformationByHandle

Ordinal 593
Address 0x24d10

GetFileInformationByHandleEx

Ordinal 594
Address 0x1f5f0

GetFileMUIInfo

Ordinal 595
Address 0x3a1d0

GetFileMUIPath

Ordinal 596
Address 0x1f940

GetFileSize

Ordinal 597
Address 0x24d20

GetFileSizeEx

Ordinal 598
Address 0x24d30

GetFileTime

Ordinal 599
Address 0x24d40

GetFileType

Ordinal 600
Address 0x24d50

GetFinalPathNameByHandleA

Ordinal 601
Address 0x24d60

GetFinalPathNameByHandleW

Ordinal 602
Address 0x24d70

GetFirmwareEnvironmentVariableA

Ordinal 603
Address 0x66200

GetFirmwareEnvironmentVariableExA

Ordinal 604
Address 0x66220

GetFirmwareEnvironmentVariableExW

Ordinal 605
Address 0x15390

GetFirmwareEnvironmentVariableW

Ordinal 606
Address 0x66350

GetFirmwareType

Ordinal 607
Address 0x227c0

GetFullPathNameA

Ordinal 608
Address 0x24d80

GetFullPathNameTransactedA

Ordinal 609
Address 0x36be0

GetFullPathNameTransactedW

Ordinal 610
Address 0x665c0

GetFullPathNameW

Ordinal 611
Address 0x24d90

GetGeoInfoA

Ordinal 612
Address 0x4b060

GetGeoInfoEx

Ordinal 613
Address 0x537b0

GetGeoInfoW

Ordinal 614
Address 0x6020

GetHandleInformation

Ordinal 615
Address 0x248a0

GetLargePageMinimum

Ordinal 616
Address 0x3a1f0

GetLargestConsoleWindowSize

Ordinal 617
Address 0x25440

GetLastError

Ordinal 618
Address 0x15b90

GetLocalTime

Ordinal 619
Address 0x1dfc0

GetLocaleInfoA

Ordinal 620
Address 0x20b70

GetLocaleInfoEx

Ordinal 621
Address 0x1cae0

GetLocaleInfoW

Ordinal 622
Address 0x1fdc0

GetLogicalDriveStringsA

Ordinal 623
Address 0x17ca0

GetLogicalDriveStringsW

Ordinal 624
Address 0x24da0

GetLogicalDrives

Ordinal 625
Address 0x17d60

GetLogicalProcessorInformation

Ordinal 626
Address 0x21010

GetLogicalProcessorInformationEx

Ordinal 627
Address 0xa0c05
ForwardName api-ms-win-core-sysinfo-l1-1-0.GetLogicalProcessorInformationEx

GetLongPathNameA

Ordinal 628
Address 0x58cc0

GetLongPathNameTransactedA

Ordinal 629
Address 0x3fd40

GetLongPathNameTransactedW

Ordinal 630
Address 0x601b0

GetLongPathNameW

Ordinal 631
Address 0x68c0

GetMailslotInfo

Ordinal 632
Address 0x61df0

GetMaximumProcessorCount

Ordinal 633
Address 0x658e0

GetMaximumProcessorGroupCount

Ordinal 634
Address 0x22760

GetMemoryErrorHandlingCapabilities

Ordinal 635
Address 0x3a210

GetModuleFileNameA

Ordinal 636
Address 0x1f140

GetModuleFileNameW

Ordinal 637
Address 0x1dec0

GetModuleHandleA

Ordinal 638
Address 0x1f050

GetModuleHandleExA

Ordinal 639
Address 0x20f30

GetModuleHandleExW

Ordinal 640
Address 0x1f5d0

GetModuleHandleW

Ordinal 641
Address 0x1d0d0

GetNLSVersion

Ordinal 642
Address 0x22130

GetNLSVersionEx

Ordinal 643
Address 0x3a230

GetNamedPipeAttribute

Ordinal 644
Address 0x3a250

GetNamedPipeClientComputerNameA

Ordinal 645
Address 0x60670

GetNamedPipeClientComputerNameW

Ordinal 646
Address 0x3a270

GetNamedPipeClientProcessId

Ordinal 647
Address 0x607c0

GetNamedPipeClientSessionId

Ordinal 648
Address 0x38090

GetNamedPipeHandleStateA

Ordinal 649
Address 0x60800

GetNamedPipeHandleStateW

Ordinal 650
Address 0x3a290

GetNamedPipeInfo

Ordinal 651
Address 0xa0e64
ForwardName api-ms-win-core-namedpipe-l1-2-1.GetNamedPipeInfo

GetNamedPipeServerProcessId

Ordinal 652
Address 0x60990

GetNamedPipeServerSessionId

Ordinal 653
Address 0x380f0

GetNativeSystemInfo

Ordinal 654
Address 0x20620

GetNextUmsListItem

Ordinal 655
Address 0x41460

GetNextVDMCommand

Ordinal 656
Address 0x3fe10

GetNumaAvailableMemoryNode

Ordinal 657
Address 0x38340

GetNumaAvailableMemoryNodeEx

Ordinal 658
Address 0x66b60

GetNumaHighestNodeNumber

Ordinal 659
Address 0x20800

GetNumaNodeNumberFromHandle

Ordinal 660
Address 0x38350

GetNumaNodeProcessorMask

Ordinal 661
Address 0x66bf0

GetNumaNodeProcessorMaskEx

Ordinal 662
Address 0x3a2b0

GetNumaProcessorNode

Ordinal 663
Address 0x383b0

GetNumaProcessorNodeEx

Ordinal 664
Address 0x66c70

GetNumaProximityNode

Ordinal 665
Address 0x38420

GetNumaProximityNodeEx

Ordinal 666
Address 0x3a2d0

GetNumberFormatA

Ordinal 667
Address 0x1ae80

GetNumberFormatEx

Ordinal 668
Address 0x21560

GetNumberFormatW

Ordinal 669
Address 0x1060

GetNumberOfConsoleFonts

Ordinal 670
Address 0x69470

GetNumberOfConsoleInputEvents

Ordinal 671
Address 0x252b0

GetNumberOfConsoleMouseButtons

Ordinal 672
Address 0x25780

GetOEMCP

Ordinal 673
Address 0x21260

GetOverlappedResult

Ordinal 674
Address 0x1c660

GetOverlappedResultEx

Ordinal 675
Address 0xa10bc
ForwardName api-ms-win-core-io-l1-1-1.GetOverlappedResultEx

GetPackageApplicationIds

Ordinal 676
Address 0xa1105
ForwardName kernelbase.GetPackageApplicationIds

GetPackageFamilyName

Ordinal 677
Address 0xa113e
ForwardName kernelbase.GetPackageFamilyName

GetPackageFullName

Ordinal 678
Address 0xa1171
ForwardName kernelbase.GetPackageFullName

GetPackageId

Ordinal 679
Address 0xa119c
ForwardName kernelbase.GetPackageId

GetPackageInfo

Ordinal 680
Address 0xa11c3
ForwardName kernelbase.GetPackageInfo

GetPackagePath

Ordinal 681
Address 0xa11ec
ForwardName kernelbase.GetPackagePath

GetPackagePathByFullName

Ordinal 682
Address 0xa121f
ForwardName kernelbase.GetPackagePathByFullName

GetPackagesByPackageFamily

Ordinal 683
Address 0xa125e
ForwardName kernelbase.GetPackagesByPackageFamily

GetPhysicallyInstalledSystemMemory

Ordinal 684
Address 0x1270

GetPriorityClass

Ordinal 685
Address 0x21060

GetPrivateProfileIntA

Ordinal 686
Address 0x15310

GetPrivateProfileIntW

Ordinal 687
Address 0x13150

GetPrivateProfileSectionA

Ordinal 688
Address 0x23120

GetPrivateProfileSectionNamesA

Ordinal 689
Address 0x5f4a0

GetPrivateProfileSectionNamesW

Ordinal 690
Address 0x5f4d0

GetPrivateProfileSectionW

Ordinal 691
Address 0x20c70

GetPrivateProfileStringA

Ordinal 692
Address 0x15200

GetPrivateProfileStringW

Ordinal 693
Address 0x12300

GetPrivateProfileStructA

Ordinal 694
Address 0x5f500

GetPrivateProfileStructW

Ordinal 695
Address 0x5f6a0

GetProcAddress

Ordinal 696
Address 0x1ae60

GetProcessAffinityMask

Ordinal 697
Address 0x1c0b0

GetProcessDEPPolicy

Ordinal 698
Address 0x39050

GetProcessDefaultCpuSets

Ordinal 699
Address 0xa140d
ForwardName api-ms-win-core-processthreads-l1-1-3.GetProcessDefaultCpuSets

GetProcessGroupAffinity

Ordinal 700
Address 0x3a2f0

GetProcessHandleCount

Ordinal 701
Address 0x3a310

GetProcessHeap

Ordinal 702
Address 0x15b50

GetProcessHeaps

Ordinal 703
Address 0x3a330

GetProcessId

Ordinal 704
Address 0x1cf70

GetProcessIdOfThread

Ordinal 705
Address 0x20780

GetProcessInformation

Ordinal 706
Address 0x24840

GetProcessIoCounters

Ordinal 707
Address 0x1fd60

GetProcessMitigationPolicy

Ordinal 708
Address 0xa1501
ForwardName api-ms-win-core-processthreads-l1-1-1.GetProcessMitigationPolicy

GetProcessPreferredUILanguages

Ordinal 709
Address 0x23e10

GetProcessPriorityBoost

Ordinal 710
Address 0x3a350

GetProcessShutdownParameters

Ordinal 711
Address 0x3a370

GetProcessTimes

Ordinal 712
Address 0x1aa70

GetProcessVersion

Ordinal 713
Address 0x22040

GetProcessWorkingSetSize

Ordinal 714
Address 0x43040

GetProcessWorkingSetSizeEx

Ordinal 715
Address 0x3a390

GetProcessorSystemCycleTime

Ordinal 716
Address 0xa1608
ForwardName api-ms-win-core-sysinfo-l1-2-2.GetProcessorSystemCycleTime

GetProductInfo

Ordinal 717
Address 0x210f0

GetProfileIntA

Ordinal 718
Address 0x15380

GetProfileIntW

Ordinal 719
Address 0x134c0

GetProfileSectionA

Ordinal 720
Address 0x5f850

GetProfileSectionW

Ordinal 721
Address 0x5f860

GetProfileStringA

Ordinal 722
Address 0x5f870

GetProfileStringW

Ordinal 723
Address 0x5f8a0

GetQueuedCompletionStatus

Ordinal 724
Address 0x15d70

GetQueuedCompletionStatusEx

Ordinal 725
Address 0x3a3b0

GetShortPathNameA

Ordinal 726
Address 0x60280

GetShortPathNameW

Ordinal 727
Address 0x6400

GetStagedPackagePathByFullName

Ordinal 728
Address 0xa1733
ForwardName kernelbase.GetStagedPackagePathByFullName

GetStartupInfoA

Ordinal 729
Address 0x21900

GetStartupInfoW

Ordinal 730
Address 0x1d7d0

GetStateFolder

Ordinal 731
Address 0xa178c
ForwardName kernelbase.GetStateFolder

GetStdHandle

Ordinal 732
Address 0x1d430

GetStringScripts

Ordinal 733
Address 0x3a3d0

GetStringTypeA

Ordinal 734
Address 0x3a3f0

GetStringTypeExA

Ordinal 735
Address 0x3a3f0

GetStringTypeExW

Ordinal 736
Address 0x22610

GetStringTypeW

Ordinal 737
Address 0x1e2d0

GetSystemAppDataKey

Ordinal 738
Address 0xa1818
ForwardName kernelbase.GetSystemAppDataKey

GetSystemCpuSetInformation

Ordinal 739
Address 0xa1852
ForwardName api-ms-win-core-processthreads-l1-1-3.GetSystemCpuSetInformation

GetSystemDEPPolicy

Ordinal 740
Address 0x390a0

GetSystemDefaultLCID

Ordinal 741
Address 0x20c50

GetSystemDefaultLangID

Ordinal 742
Address 0x20f90

GetSystemDefaultLocaleName

Ordinal 743
Address 0x1100

GetSystemDefaultUILanguage

Ordinal 744
Address 0x20600

GetSystemDirectoryA

Ordinal 745
Address 0x1d380

GetSystemDirectoryW

Ordinal 746
Address 0x1ada0

GetSystemFileCacheSize

Ordinal 747
Address 0x3a410

GetSystemFirmwareTable

Ordinal 748
Address 0x37b00

GetSystemInfo

Ordinal 749
Address 0x1db50

GetSystemPowerStatus

Ordinal 750
Address 0x17b60

GetSystemPreferredUILanguages

Ordinal 751
Address 0x212e0

GetSystemRegistryQuota

Ordinal 752
Address 0x390e0

GetSystemTime

Ordinal 753
Address 0x1b520

GetSystemTimeAdjustment

Ordinal 754
Address 0x206e0

GetSystemTimeAsFileTime

Ordinal 755
Address 0x17b20

GetSystemTimePreciseAsFileTime

Ordinal 756
Address 0x24fe0

GetSystemTimes

Ordinal 757
Address 0x1fc30

GetSystemWindowsDirectoryA

Ordinal 758
Address 0x3a430

GetSystemWindowsDirectoryW

Ordinal 759
Address 0x9110

GetSystemWow64DirectoryA

Ordinal 760
Address 0x25150

GetSystemWow64DirectoryW

Ordinal 761
Address 0x25160

GetTapeParameters

Ordinal 762
Address 0x66e40

GetTapePosition

Ordinal 763
Address 0x42660

GetTapeStatus

Ordinal 764
Address 0x426f0

GetTempFileNameA

Ordinal 765
Address 0x24db0

GetTempFileNameW

Ordinal 766
Address 0x24dc0

GetTempPathA

Ordinal 767
Address 0x24dd0

GetTempPathW

Ordinal 768
Address 0x24de0

GetThreadContext

Ordinal 769
Address 0x20510

GetThreadDescription

Ordinal 770
Address 0xa1b1c
ForwardName api-ms-win-core-processthreads-l1-1-3.GetThreadDescription

GetThreadErrorMode

Ordinal 771
Address 0x3a440

GetThreadGroupAffinity

Ordinal 772
Address 0x3a460

GetThreadIOPendingFlag

Ordinal 773
Address 0x3a480

GetThreadId

Ordinal 774
Address 0x20bb0

GetThreadIdealProcessorEx

Ordinal 775
Address 0x3a4a0

GetThreadInformation

Ordinal 776
Address 0x24850

GetThreadLocale

Ordinal 777
Address 0x1a090

GetThreadPreferredUILanguages

Ordinal 778
Address 0x1d050

GetThreadPriority

Ordinal 779
Address 0x1b820

GetThreadPriorityBoost

Ordinal 780
Address 0x3a4c0

GetThreadSelectedCpuSets

Ordinal 781
Address 0xa1c43
ForwardName api-ms-win-core-processthreads-l1-1-3.GetThreadSelectedCpuSets

GetThreadSelectorEntry

Ordinal 782
Address 0x66ea0

GetThreadTimes

Ordinal 783
Address 0x15bd0

GetThreadUILanguage

Ordinal 784
Address 0x242d0

GetTickCount

Ordinal 785
Address 0x155e0

GetTickCount64

Ordinal 786
Address 0x15cd0

GetTimeFormatA

Ordinal 787
Address 0x3a4e0

GetTimeFormatAWorker

Ordinal 788
Address 0x23e30

GetTimeFormatEx

Ordinal 789
Address 0x3a500

GetTimeFormatW

Ordinal 790
Address 0x1f160

GetTimeFormatWWorker

Ordinal 791
Address 0x9a80

GetTimeZoneInformation

Ordinal 792
Address 0x208a0

GetTimeZoneInformationForYear

Ordinal 793
Address 0x1070

GetUILanguageInfo

Ordinal 794
Address 0x3a520

GetUmsCompletionListEvent

Ordinal 795
Address 0x414a0

GetUmsSystemThreadInformation

Ordinal 796
Address 0x414e0

GetUserDefaultGeoName

Ordinal 797
Address 0x53910

GetUserDefaultLCID

Ordinal 798
Address 0x1fb40

GetUserDefaultLangID

Ordinal 799
Address 0x3a540

GetUserDefaultLocaleName

Ordinal 800
Address 0x1e310

GetUserDefaultUILanguage

Ordinal 801
Address 0x20ad0

GetUserGeoID

Ordinal 802
Address 0x1f180

GetUserPreferredUILanguages

Ordinal 803
Address 0x20530

GetVDMCurrentDirectories

Ordinal 804
Address 0x407d0

GetVersion

Ordinal 805
Address 0x20fb0

GetVersionExA

Ordinal 806
Address 0x203a0

GetVersionExW

Ordinal 807
Address 0x1f920

GetVolumeInformationA

Ordinal 808
Address 0x24df0

GetVolumeInformationByHandleW

Ordinal 809
Address 0x24e00

GetVolumeInformationW

Ordinal 810
Address 0x24e10

GetVolumeNameForVolumeMountPointA

Ordinal 811
Address 0x23f70

GetVolumeNameForVolumeMountPointW

Ordinal 812
Address 0x24810

GetVolumePathNameA

Ordinal 813
Address 0x64e40

GetVolumePathNameW

Ordinal 814
Address 0x24e20

GetVolumePathNamesForVolumeNameA

Ordinal 815
Address 0x65020

GetVolumePathNamesForVolumeNameW

Ordinal 816
Address 0x24e30

GetWindowsDirectoryA

Ordinal 817
Address 0x221d0

GetWindowsDirectoryW

Ordinal 818
Address 0x22860

GetWriteWatch

Ordinal 819
Address 0x15b70

GetXStateFeaturesMask

Ordinal 820
Address 0x3a560

GlobalAddAtomA

Ordinal 821
Address 0x12600

GlobalAddAtomExA

Ordinal 822
Address 0x59200

GlobalAddAtomExW

Ordinal 823
Address 0x13130

GlobalAddAtomW

Ordinal 824
Address 0x128b0

GlobalAlloc

Ordinal 825
Address 0x17db0

GlobalCompact

Ordinal 826
Address 0x37b20

GlobalDeleteAtom

Ordinal 827
Address 0x127f0

GlobalFindAtomA

Ordinal 828
Address 0x59220

GlobalFindAtomW

Ordinal 829
Address 0x12da0

GlobalFix

Ordinal 830
Address 0x37b40

GlobalFlags

Ordinal 831
Address 0x1f9b0

GlobalFree

Ordinal 832
Address 0x15af0

GlobalGetAtomNameA

Ordinal 833
Address 0x59240

GlobalGetAtomNameW

Ordinal 834
Address 0x12620

GlobalHandle

Ordinal 835
Address 0x20090

GlobalLock

Ordinal 836
Address 0x15930

GlobalMemoryStatus

Ordinal 837
Address 0x1c8a0

GlobalMemoryStatusEx

Ordinal 838
Address 0x204d0

GlobalReAlloc

Ordinal 839
Address 0x16b50

GlobalSize

Ordinal 840
Address 0x17dd0

GlobalUnWire

Ordinal 841
Address 0x37b60

GlobalUnfix

Ordinal 842
Address 0x37b70

GlobalUnlock

Ordinal 843
Address 0x15850

GlobalWire

Ordinal 844
Address 0x37b90

Heap32First

Ordinal 845
Address 0x63050

Heap32ListFirst

Ordinal 846
Address 0x632f0

Heap32ListNext

Ordinal 847
Address 0x633f0

Heap32Next

Ordinal 848
Address 0x634f0

HeapAlloc

Ordinal 849
Address 0xa2168
ForwardName NTDLL.RtlAllocateHeap

HeapCompact

Ordinal 850
Address 0x3a580

HeapCreate

Ordinal 851
Address 0x1fef0

HeapDestroy

Ordinal 852
Address 0x21240

HeapFree

Ordinal 853
Address 0x15510

HeapLock

Ordinal 854
Address 0x3a5a0

HeapQueryInformation

Ordinal 855
Address 0x3a5c0

HeapReAlloc

Ordinal 856
Address 0xa21d4
ForwardName NTDLL.RtlReAllocateHeap

HeapSetInformation

Ordinal 857
Address 0x20380

HeapSize

Ordinal 858
Address 0xa2208
ForwardName NTDLL.RtlSizeHeap

HeapSummary

Ordinal 859
Address 0x3a5e0

HeapUnlock

Ordinal 860
Address 0x3a600

HeapValidate

Ordinal 861
Address 0x1c090

HeapWalk

Ordinal 862
Address 0x3a620

IdnToAscii

Ordinal 863
Address 0x1090

IdnToNameprepUnicode

Ordinal 864
Address 0x3a640

IdnToUnicode

Ordinal 865
Address 0x3a660

InitAtomTable

Ordinal 866
Address 0x59270

InitOnceBeginInitialize

Ordinal 867
Address 0xa229a
ForwardName api-ms-win-core-synch-l1-2-0.InitOnceBeginInitialize

InitOnceComplete

Ordinal 868
Address 0xa22e0
ForwardName api-ms-win-core-synch-l1-2-0.InitOnceComplete

InitOnceExecuteOnce

Ordinal 869
Address 0xa2322
ForwardName api-ms-win-core-synch-l1-2-0.InitOnceExecuteOnce

InitOnceInitialize

Ordinal 870
Address 0xa2366
ForwardName NTDLL.RtlRunOnceInitialize

InitializeConditionVariable

Ordinal 871
Address 0xa239d
ForwardName NTDLL.RtlInitializeConditionVariable

InitializeContext

Ordinal 872
Address 0x3a6a0

InitializeContext2

Ordinal 873
Address 0x3a680

InitializeCriticalSection

Ordinal 874
Address 0xa2401
ForwardName NTDLL.RtlInitializeCriticalSection

InitializeCriticalSectionAndSpinCount

Ordinal 875
Address 0x24980

InitializeCriticalSectionEx

Ordinal 876
Address 0x24990

InitializeEnclave

Ordinal 877
Address 0xa2478
ForwardName api-ms-win-core-enclave-l1-1-0.InitializeEnclave

InitializeProcThreadAttributeList

Ordinal 878
Address 0xa24cb
ForwardName api-ms-win-core-processthreads-l1-1-0.InitializeProcThreadAttributeList

InitializeSListHead

Ordinal 879
Address 0xa2527
ForwardName NTDLL.RtlInitializeSListHead

InitializeSRWLock

Ordinal 880
Address 0xa2556
ForwardName NTDLL.RtlInitializeSRWLock

InitializeSynchronizationBarrier

Ordinal 881
Address 0x3a6c0

InstallELAMCertificateInfo

Ordinal 882
Address 0xa25ad
ForwardName api-ms-win-core-sysinfo-l1-2-1.InstallELAMCertificateInfo

InterlockedFlushSList

Ordinal 883
Address 0xa25fd
ForwardName NTDLL.RtlInterlockedFlushSList

InterlockedPopEntrySList

Ordinal 884
Address 0xa2635
ForwardName NTDLL.RtlInterlockedPopEntrySList

InterlockedPushEntrySList

Ordinal 885
Address 0xa2671
ForwardName NTDLL.RtlInterlockedPushEntrySList

InterlockedPushListSList

Ordinal 886
Address 0xa26ad
ForwardName NTDLL.RtlInterlockedPushListSList

InterlockedPushListSListEx

Ordinal 887
Address 0xa26ea
ForwardName NTDLL.RtlInterlockedPushListSListEx

InvalidateConsoleDIBits

Ordinal 888
Address 0x69590

IsBadCodePtr

Ordinal 889
Address 0x39170

IsBadHugeReadPtr

Ordinal 890
Address 0x39180

IsBadHugeWritePtr

Ordinal 891
Address 0x39190

IsBadReadPtr

Ordinal 892
Address 0x15a40

IsBadStringPtrA

Ordinal 893
Address 0x391a0

IsBadStringPtrW

Ordinal 894
Address 0x391f0

IsBadWritePtr

Ordinal 895
Address 0x659a0

IsCalendarLeapDay

Ordinal 896
Address 0x4a0b0

IsCalendarLeapMonth

Ordinal 897
Address 0x4a190

IsCalendarLeapYear

Ordinal 898
Address 0x4a280

IsDBCSLeadByte

Ordinal 899
Address 0x218e0

IsDBCSLeadByteEx

Ordinal 900
Address 0x3a6e0

IsDebuggerPresent

Ordinal 901
Address 0x20150

IsEnclaveTypeSupported

Ordinal 902
Address 0xa2813
ForwardName api-ms-win-core-enclave-l1-1-0.IsEnclaveTypeSupported

IsNLSDefinedString

Ordinal 903
Address 0x3a700

IsNativeVhdBoot

Ordinal 904
Address 0x369a0

IsNormalizedString

Ordinal 905
Address 0x3a720

IsProcessCritical

Ordinal 906
Address 0xa2891
ForwardName api-ms-win-core-processthreads-l1-1-2.IsProcessCritical

IsProcessInJob

Ordinal 907
Address 0x20860

IsProcessorFeaturePresent

Ordinal 908
Address 0x1dae0

IsSystemResumeAutomatic

Ordinal 909
Address 0x38670

IsThreadAFiber

Ordinal 910
Address 0x1d090

IsThreadpoolTimerSet

Ordinal 911
Address 0xa292e
ForwardName NTDLL.TpIsTimerSet

IsUserCetAvailableInEnvironment

Ordinal 912
Address 0xa2961
ForwardName api-ms-win-core-sysinfo-l1-2-6.IsUserCetAvailableInEnvironment

IsValidCalDateTime

Ordinal 913
Address 0x82b0

IsValidCodePage

Ordinal 914
Address 0x1fc10

IsValidLanguageGroup

Ordinal 915
Address 0x3a740

IsValidLocale

Ordinal 916
Address 0x1fe40

IsValidLocaleName

Ordinal 917
Address 0x3a760

IsValidNLSVersion

Ordinal 918
Address 0x3a780

IsWow64GuestMachineSupported

Ordinal 919
Address 0xa2a27
ForwardName api-ms-win-core-wow64-l1-1-2.IsWow64GuestMachineSupported

IsWow64Process

Ordinal 920
Address 0x1f610

IsWow64Process2

Ordinal 921
Address 0xa2a80
ForwardName api-ms-win-core-wow64-l1-1-1.IsWow64Process2

K32EmptyWorkingSet

Ordinal 922
Address 0x3a7a0

K32EnumDeviceDrivers

Ordinal 923
Address 0x3a7c0

K32EnumPageFilesA

Ordinal 924
Address 0x3a7e0

K32EnumPageFilesW

Ordinal 925
Address 0x3a800

K32EnumProcessModules

Ordinal 926
Address 0x21080

K32EnumProcessModulesEx

Ordinal 927
Address 0x3a820

K32EnumProcesses

Ordinal 928
Address 0x3a840

K32GetDeviceDriverBaseNameA

Ordinal 929
Address 0x3a860

K32GetDeviceDriverBaseNameW

Ordinal 930
Address 0x3a880

K32GetDeviceDriverFileNameA

Ordinal 931
Address 0x3a8a0

K32GetDeviceDriverFileNameW

Ordinal 932
Address 0x3a8c0

K32GetMappedFileNameA

Ordinal 933
Address 0x3a8e0

K32GetMappedFileNameW

Ordinal 934
Address 0x3a900

K32GetModuleBaseNameA

Ordinal 935
Address 0x3a920

K32GetModuleBaseNameW

Ordinal 936
Address 0x3a940

K32GetModuleFileNameExA

Ordinal 937
Address 0x3a960

K32GetModuleFileNameExW

Ordinal 938
Address 0x24290

K32GetModuleInformation

Ordinal 939
Address 0x1f070

K32GetPerformanceInfo

Ordinal 940
Address 0x3a980

K32GetProcessImageFileNameA

Ordinal 941
Address 0x3a9a0

K32GetProcessImageFileNameW

Ordinal 942
Address 0x20000

K32GetProcessMemoryInfo

Ordinal 943
Address 0x3a9c0

K32GetWsChanges

Ordinal 944
Address 0x3aa00

K32GetWsChangesEx

Ordinal 945
Address 0x3a9e0

K32InitializeProcessForWsWatch

Ordinal 946
Address 0x3aa20

K32QueryWorkingSet

Ordinal 947
Address 0x3aa60

K32QueryWorkingSetEx

Ordinal 948
Address 0x3aa40

LCIDToLocaleName

Ordinal 949
Address 0x205e0

LCMapStringA

Ordinal 950
Address 0x3aa80

LCMapStringEx

Ordinal 951
Address 0x15c70

LCMapStringW

Ordinal 952
Address 0x18440

LZClose

Ordinal 953
Address 0x3c130

LZCloseFile

Ordinal 954
Address 0x3c1f0

LZCopy

Ordinal 955
Address 0x36ad0

LZCreateFileW

Ordinal 956
Address 0x3c2c0

LZDone

Ordinal 957
Address 0x36bd0

LZInit

Ordinal 958
Address 0x3c400

LZOpenFileA

Ordinal 959
Address 0x3c5b0

LZOpenFileW

Ordinal 960
Address 0x3c6a0

LZRead

Ordinal 961
Address 0x3c760

LZSeek

Ordinal 962
Address 0x3c9d0

LZStart

Ordinal 963
Address 0x21380

LeaveCriticalSection

Ordinal 964
Address 0xa2dca
ForwardName NTDLL.RtlLeaveCriticalSection

LeaveCriticalSectionWhenCallbackReturns

Ordinal 965
Address 0xa2e10
ForwardName NTDLL.TpCallbackLeaveCriticalSectionOnCompletion

LoadAppInitDlls

Ordinal 966
Address 0x17f30

LoadEnclaveData

Ordinal 967
Address 0xa2e61
ForwardName api-ms-win-core-enclave-l1-1-0.LoadEnclaveData

LoadLibraryA

Ordinal 968
Address 0x20490

LoadLibraryExA

Ordinal 969
Address 0x1fb60

LoadLibraryExW

Ordinal 970
Address 0x1ad60

LoadLibraryW

Ordinal 971
Address 0x1fe80

LoadModule

Ordinal 972
Address 0x65a30

LoadPackagedLibrary

Ordinal 973
Address 0x24fc0

LoadResource

Ordinal 974
Address 0x1b300

LoadStringBaseExW

Ordinal 975
Address 0x3aaa0

LoadStringBaseW

Ordinal 976
Address 0x37cd0

LocalAlloc

Ordinal 977
Address 0x18460

LocalCompact

Ordinal 978
Address 0x37b20

LocalFileTimeToFileTime

Ordinal 979
Address 0x24e40

LocalFileTimeToLocalSystemTime

Ordinal 980
Address 0xa2f65
ForwardName api-ms-win-core-timezone-l1-1-1.LocalFileTimeToLocalSystemTime

LocalFlags

Ordinal 981
Address 0x66ec0

LocalFree

Ordinal 982
Address 0x17b00

LocalHandle

Ordinal 983
Address 0x37bd0

LocalLock

Ordinal 984
Address 0x3aac0

LocalReAlloc

Ordinal 985
Address 0x1fd00

LocalShrink

Ordinal 986
Address 0x37b20

LocalSize

Ordinal 987
Address 0x1b3c0

LocalSystemTimeToLocalFileTime

Ordinal 988
Address 0xa3011
ForwardName api-ms-win-core-timezone-l1-1-1.LocalSystemTimeToLocalFileTime

LocalUnlock

Ordinal 989
Address 0x3aae0

LocaleNameToLCID

Ordinal 990
Address 0x1e020

LocateXStateFeature

Ordinal 991
Address 0x3ab00

LockFile

Ordinal 992
Address 0x24e50

LockFileEx

Ordinal 993
Address 0x24e60

LockResource

Ordinal 994
Address 0x1b360

MapUserPhysicalPages

Ordinal 995
Address 0x3ab20

MapUserPhysicalPagesScatter

Ordinal 996
Address 0x43070

MapViewOfFile

Ordinal 997
Address 0x1d790

MapViewOfFileEx

Ordinal 998
Address 0x1c990

MapViewOfFileExNuma

Ordinal 999
Address 0x3ab40

MapViewOfFileFromApp

Ordinal 1000
Address 0xa311a
ForwardName api-ms-win-core-memory-l1-1-1.MapViewOfFileFromApp

Module32First

Ordinal 1001
Address 0x637a0

Module32FirstW

Ordinal 1002
Address 0x1db70

Module32Next

Ordinal 1003
Address 0x638e0

Module32NextW

Ordinal 1004
Address 0x19f40

MoveFileA

Ordinal 1005
Address 0x62810

MoveFileExA

Ordinal 1006
Address 0x62840

MoveFileExW

Ordinal 1007
Address 0x20c30

MoveFileTransactedA

Ordinal 1008
Address 0x62870

MoveFileTransactedW

Ordinal 1009
Address 0x23d50

MoveFileW

Ordinal 1010
Address 0x22830

MoveFileWithProgressA

Ordinal 1011
Address 0x62950

MoveFileWithProgressW

Ordinal 1012
Address 0x3ab60

MulDiv

Ordinal 1013
Address 0x24fa0

MultiByteToWideChar

Ordinal 1014
Address 0x157b0

NeedCurrentDirectoryForExePathA

Ordinal 1015
Address 0x3ab80

NeedCurrentDirectoryForExePathW

Ordinal 1016
Address 0x3aba0

NlsCheckPolicy

Ordinal 1017
Address 0x251f0

NlsGetCacheUpdateCount

Ordinal 1018
Address 0x25200

NlsUpdateLocale

Ordinal 1019
Address 0x25210

NlsUpdateSystemLocale

Ordinal 1020
Address 0x25220

NormalizeString

Ordinal 1021
Address 0x3abc0

NotifyMountMgr

Ordinal 1022
Address 0x3abe0

NotifyUILanguageChange

Ordinal 1023
Address 0x4d460

NtVdm64CreateProcessInternalW

Ordinal 1024
Address 0x39250

OOBEComplete

Ordinal 1025
Address 0x1ea20

OfferVirtualMemory

Ordinal 1026
Address 0xa3320
ForwardName api-ms-win-core-memory-l1-1-2.OfferVirtualMemory

OpenConsoleW

Ordinal 1027
Address 0x689a0

OpenConsoleWStub

Ordinal 1028
Address 0x3ac00

OpenEventA

Ordinal 1029
Address 0x249a0

OpenEventW

Ordinal 1030
Address 0x249b0

OpenFile

Ordinal 1031
Address 0x61340

OpenFileById

Ordinal 1032
Address 0x3ac10

OpenFileMappingA

Ordinal 1033
Address 0x215b0

OpenFileMappingW

Ordinal 1034
Address 0x206c0

OpenJobObjectA

Ordinal 1035
Address 0x5b390

OpenJobObjectW

Ordinal 1036
Address 0x5b410

OpenMutexA

Ordinal 1037
Address 0x1bfc0

OpenMutexW

Ordinal 1038
Address 0x249c0

OpenPackageInfoByFullName

Ordinal 1039
Address 0xa340b
ForwardName kernelbase.OpenPackageInfoByFullName

OpenPrivateNamespaceA

Ordinal 1040
Address 0x60cd0

OpenPrivateNamespaceW

Ordinal 1041
Address 0x22230

OpenProcess

Ordinal 1042
Address 0x1ad80

OpenProcessToken

Ordinal 1043
Address 0xa3479
ForwardName api-ms-win-core-processthreads-l1-1-0.OpenProcessToken

OpenProfileUserMapping

Ordinal 1044
Address 0x21380

OpenSemaphoreA

Ordinal 1045
Address 0x62010

OpenSemaphoreW

Ordinal 1046
Address 0x249d0

OpenState

Ordinal 1047
Address 0xa34ef
ForwardName kernelbase.OpenState

OpenStateExplicit

Ordinal 1048
Address 0xa3516
ForwardName kernelbase.OpenStateExplicit

OpenThread

Ordinal 1049
Address 0x1c7f0

OpenThreadToken

Ordinal 1050
Address 0xa354e
ForwardName api-ms-win-core-processthreads-l1-1-0.OpenThreadToken

OpenWaitableTimerA

Ordinal 1051
Address 0x62080

OpenWaitableTimerW

Ordinal 1052
Address 0x249e0

OutputDebugStringA

Ordinal 1053
Address 0x24270

OutputDebugStringW

Ordinal 1054
Address 0x1d0b0

PackageFamilyNameFromFullName

Ordinal 1055
Address 0xa35ee
ForwardName kernelbase.PackageFamilyNameFromFullName

PackageFamilyNameFromId

Ordinal 1056
Address 0xa362f
ForwardName kernelbase.PackageFamilyNameFromId

PackageFullNameFromId

Ordinal 1057
Address 0xa3668
ForwardName kernelbase.PackageFullNameFromId

PackageIdFromFullName

Ordinal 1058
Address 0xa369f
ForwardName kernelbase.PackageIdFromFullName

PackageNameAndPublisherIdFromFamilyName

Ordinal 1059
Address 0xa36e8
ForwardName kernelbase.PackageNameAndPublisherIdFromFamilyName

ParseApplicationUserModelId

Ordinal 1060
Address 0xa3737
ForwardName kernelbase.ParseApplicationUserModelId

PeekConsoleInputA

Ordinal 1061
Address 0x252c0

PeekConsoleInputW

Ordinal 1062
Address 0x252d0

PeekNamedPipe

Ordinal 1063
Address 0x3ac30

PostQueuedCompletionStatus

Ordinal 1064
Address 0x1b340

PowerClearRequest

Ordinal 1065
Address 0x1fc70

PowerCreateRequest

Ordinal 1066
Address 0x1eda0

PowerSetRequest

Ordinal 1067
Address 0x1fb80

PrefetchVirtualMemory

Ordinal 1068
Address 0xa37f6
ForwardName api-ms-win-core-memory-l1-1-1.PrefetchVirtualMemory

PrepareTape

Ordinal 1069
Address 0x42720

PrivCopyFileExW

Ordinal 1070
Address 0x225d0

PrivMoveFileIdentityW

Ordinal 1071
Address 0x62a60

Process32First

Ordinal 1072
Address 0x63a10

Process32FirstW

Ordinal 1073
Address 0x22630

Process32Next

Ordinal 1074
Address 0x63b10

Process32NextW

Ordinal 1075
Address 0x223d0

ProcessIdToSessionId

Ordinal 1076
Address 0x1c790

PssCaptureSnapshot

Ordinal 1077
Address 0x3ac50

PssDuplicateSnapshot

Ordinal 1078
Address 0x3ac70

PssFreeSnapshot

Ordinal 1079
Address 0x3ac90

PssQuerySnapshot

Ordinal 1080
Address 0x3acb0

PssWalkMarkerCreate

Ordinal 1081
Address 0x3acd0

PssWalkMarkerFree

Ordinal 1082
Address 0x3acf0

PssWalkMarkerGetPosition

Ordinal 1083
Address 0x3ad10

PssWalkMarkerRewind

Ordinal 1084
Address 0x3ad30

PssWalkMarkerSeek

Ordinal 1085
Address 0x3ad50

PssWalkMarkerSeekToBeginning

Ordinal 1086
Address 0x3ad30

PssWalkMarkerSetPosition

Ordinal 1087
Address 0x3ad50

PssWalkMarkerTell

Ordinal 1088
Address 0x3ad10

PssWalkSnapshot

Ordinal 1089
Address 0x3ad70

PulseEvent

Ordinal 1090
Address 0x1c250

PurgeComm

Ordinal 1091
Address 0x250c0

QueryActCtxSettingsW

Ordinal 1092
Address 0x3ad90

QueryActCtxSettingsWWorker

Ordinal 1093
Address 0x12b10

QueryActCtxW

Ordinal 1094
Address 0x1df40

QueryActCtxWWorker

Ordinal 1095
Address 0x12470

QueryDepthSList

Ordinal 1096
Address 0xa3a28
ForwardName NTDLL.RtlQueryDepthSList

QueryDosDeviceA

Ordinal 1097
Address 0x63cb0

QueryDosDeviceW

Ordinal 1098
Address 0x24e70

QueryFullProcessImageNameA

Ordinal 1099
Address 0x3adb0

QueryFullProcessImageNameW

Ordinal 1100
Address 0x1c810

QueryIdleProcessorCycleTime

Ordinal 1101
Address 0x21ea0

QueryIdleProcessorCycleTimeEx

Ordinal 1102
Address 0x3add0

QueryInformationJobObject

Ordinal 1103
Address 0x1d7f0

QueryIoRateControlInformationJobObject

Ordinal 1104
Address 0x5b4e0

QueryMemoryResourceNotification

Ordinal 1105
Address 0x3adf0

QueryPerformanceCounter

Ordinal 1106
Address 0x15bb0

QueryPerformanceFrequency

Ordinal 1107
Address 0x1ae40

QueryProcessAffinityUpdateMode

Ordinal 1108
Address 0x3ae10

QueryProcessCycleTime

Ordinal 1109
Address 0x21ec0

QueryProtectedPolicy

Ordinal 1110
Address 0xa3bae
ForwardName api-ms-win-core-processthreads-l1-1-2.QueryProtectedPolicy

QueryThreadCycleTime

Ordinal 1111
Address 0x10e0

QueryThreadProfiling

Ordinal 1112
Address 0x43220

QueryThreadpoolStackInformation

Ordinal 1113
Address 0x3ae30

QueryUmsThreadInformation

Ordinal 1114
Address 0x41560

QueryUnbiasedInterruptTime

Ordinal 1115
Address 0x1d070

QueueUserAPC

Ordinal 1116
Address 0x1e080

QueueUserWorkItem

Ordinal 1117
Address 0x20f50

QuirkGetData2Worker

Ordinal 1118
Address 0x6fe70

QuirkGetDataWorker

Ordinal 1119
Address 0x6ff40

QuirkIsEnabled2Worker

Ordinal 1120
Address 0x70000

QuirkIsEnabled3Worker

Ordinal 1121
Address 0x15d00

QuirkIsEnabledForPackage2Worker

Ordinal 1122
Address 0x70150

QuirkIsEnabledForPackage3Worker

Ordinal 1123
Address 0x9c60

QuirkIsEnabledForPackage4Worker

Ordinal 1124
Address 0x9dd0

QuirkIsEnabledForPackageWorker

Ordinal 1125
Address 0x9060

QuirkIsEnabledForProcessWorker

Ordinal 1126
Address 0x1f380

QuirkIsEnabledWorker

Ordinal 1127
Address 0x9120

RaiseException

Ordinal 1128
Address 0x1fc50

RaiseFailFastException

Ordinal 1129
Address 0xa3db3
ForwardName kernelbase.RaiseFailFastException

RaiseInvalid16BitExeError

Ordinal 1130
Address 0x39460

ReOpenFile

Ordinal 1131
Address 0x3ae70

ReadConsoleA

Ordinal 1132
Address 0x252e0

ReadConsoleInputA

Ordinal 1133
Address 0x252f0

ReadConsoleInputExA

Ordinal 1134
Address 0xa3e2d
ForwardName kernelbase.ReadConsoleInputExA

ReadConsoleInputExW

Ordinal 1135
Address 0xa3e60
ForwardName kernelbase.ReadConsoleInputExW

ReadConsoleInputW

Ordinal 1136
Address 0x25300

ReadConsoleOutputA

Ordinal 1137
Address 0x25450

ReadConsoleOutputAttribute

Ordinal 1138
Address 0x25460

ReadConsoleOutputCharacterA

Ordinal 1139
Address 0x25470

ReadConsoleOutputCharacterW

Ordinal 1140
Address 0x25480

ReadConsoleOutputW

Ordinal 1141
Address 0x25490

ReadConsoleW

Ordinal 1142
Address 0x25310

ReadDirectoryChangesExW

Ordinal 1143
Address 0x3ae90

ReadDirectoryChangesW

Ordinal 1144
Address 0x24250

ReadFile

Ordinal 1145
Address 0x24e80

ReadFileEx

Ordinal 1146
Address 0x24e90

ReadFileScatter

Ordinal 1147
Address 0x24ea0

ReadProcessMemory

Ordinal 1148
Address 0x1c490

ReadThreadProfilingData

Ordinal 1149
Address 0x43260

ReclaimVirtualMemory

Ordinal 1150
Address 0xa3fa8
ForwardName api-ms-win-core-memory-l1-1-2.ReclaimVirtualMemory

RegCloseKey

Ordinal 1151
Address 0x241c0

RegCopyTreeW

Ordinal 1152
Address 0x3aeb0

RegCreateKeyExA

Ordinal 1153
Address 0x3aed0

RegCreateKeyExW

Ordinal 1154
Address 0x3aef0

RegDeleteKeyExA

Ordinal 1155
Address 0x3af10

RegDeleteKeyExW

Ordinal 1156
Address 0x3af30

RegDeleteTreeA

Ordinal 1157
Address 0x3af50

RegDeleteTreeW

Ordinal 1158
Address 0x3af70

RegDeleteValueA

Ordinal 1159
Address 0x3af90

RegDeleteValueW

Ordinal 1160
Address 0x3afb0

RegDisablePredefinedCacheEx

Ordinal 1161
Address 0x3afd0

RegEnumKeyExA

Ordinal 1162
Address 0x3aff0

RegEnumKeyExW

Ordinal 1163
Address 0x3b040

RegEnumValueA

Ordinal 1164
Address 0x3b090

RegEnumValueW

Ordinal 1165
Address 0x3b0e0

RegFlushKey

Ordinal 1166
Address 0x3b130

RegGetKeySecurity

Ordinal 1167
Address 0x3b150

RegGetValueA

Ordinal 1168
Address 0x3b170

RegGetValueW

Ordinal 1169
Address 0x21d90

RegLoadKeyA

Ordinal 1170
Address 0x3b190

RegLoadKeyW

Ordinal 1171
Address 0x3b1b0

RegLoadMUIStringA

Ordinal 1172
Address 0x3b1d0

RegLoadMUIStringW

Ordinal 1173
Address 0x3b1f0

RegNotifyChangeKeyValue

Ordinal 1174
Address 0x3b210

RegOpenCurrentUser

Ordinal 1175
Address 0x22270

RegOpenKeyExA

Ordinal 1176
Address 0x3b230

RegOpenKeyExW

Ordinal 1177
Address 0x209a0

RegOpenUserClassesRoot

Ordinal 1178
Address 0x22250

RegQueryInfoKeyA

Ordinal 1179
Address 0x3b250

RegQueryInfoKeyW

Ordinal 1180
Address 0x3b2d0

RegQueryValueExA

Ordinal 1181
Address 0x3b350

RegQueryValueExW

Ordinal 1182
Address 0x3b370

RegRestoreKeyA

Ordinal 1183
Address 0x3b390

RegRestoreKeyW

Ordinal 1184
Address 0x3b3b0

RegSaveKeyExA

Ordinal 1185
Address 0x3b3d0

RegSaveKeyExW

Ordinal 1186
Address 0x3b3f0

RegSetKeySecurity

Ordinal 1187
Address 0x3b410

RegSetValueExA

Ordinal 1188
Address 0x3b430

RegSetValueExW

Ordinal 1189
Address 0x3b450

RegUnLoadKeyA

Ordinal 1190
Address 0x3b470

RegUnLoadKeyW

Ordinal 1191
Address 0x3b490

RegisterApplicationRecoveryCallback

Ordinal 1192
Address 0x21630

RegisterApplicationRestart

Ordinal 1193
Address 0x212c0

RegisterBadMemoryNotification

Ordinal 1194
Address 0x3b4b0

RegisterConsoleIME

Ordinal 1195
Address 0x69070

RegisterConsoleOS2

Ordinal 1196
Address 0x690a0

RegisterConsoleVDM

Ordinal 1197
Address 0x68ae0

RegisterWaitForInputIdle

Ordinal 1198
Address 0x1f980

RegisterWaitForSingleObject

Ordinal 1199
Address 0x15470

RegisterWaitForSingleObjectEx

Ordinal 1200
Address 0x3b4d0

RegisterWaitUntilOOBECompleted

Ordinal 1201
Address 0x1e960

RegisterWowBaseHandlers

Ordinal 1202
Address 0x37ba0

RegisterWowExec

Ordinal 1203
Address 0x40d60

ReleaseActCtx

Ordinal 1204
Address 0x211c0

ReleaseActCtxWorker

Ordinal 1205
Address 0x1d7b0

ReleaseMutex

Ordinal 1206
Address 0x249f0

ReleaseMutexWhenCallbackReturns

Ordinal 1207
Address 0xa43e1
ForwardName NTDLL.TpCallbackReleaseMutexOnCompletion

ReleaseSRWLockExclusive

Ordinal 1208
Address 0xa4422
ForwardName NTDLL.RtlReleaseSRWLockExclusive

ReleaseSRWLockShared

Ordinal 1209
Address 0xa4458
ForwardName NTDLL.RtlReleaseSRWLockShared

ReleaseSemaphore

Ordinal 1210
Address 0x24a00

ReleaseSemaphoreWhenCallbackReturns

Ordinal 1211
Address 0xa44ab
ForwardName NTDLL.TpCallbackReleaseSemaphoreOnCompletion

RemoveDirectoryA

Ordinal 1212
Address 0x24eb0

RemoveDirectoryTransactedA

Ordinal 1213
Address 0x36ed0

RemoveDirectoryTransactedW

Ordinal 1214
Address 0x61b80

RemoveDirectoryW

Ordinal 1215
Address 0x24ec0

RemoveDllDirectory

Ordinal 1216
Address 0xa4543
ForwardName api-ms-win-core-libraryloader-l1-1-0.RemoveDllDirectory

RemoveLocalAlternateComputerNameA

Ordinal 1217
Address 0x5a6c0

RemoveLocalAlternateComputerNameW

Ordinal 1218
Address 0x5a720

RemoveSecureMemoryCacheCallback

Ordinal 1219
Address 0x37bb0

RemoveVectoredContinueHandler

Ordinal 1220
Address 0xa45fd
ForwardName NTDLL.RtlRemoveVectoredContinueHandler

RemoveVectoredExceptionHandler

Ordinal 1221
Address 0xa4643
ForwardName NTDLL.RtlRemoveVectoredExceptionHandler

ReplaceFile

Ordinal 1222
Address 0x3b4f0

ReplaceFileA

Ordinal 1223
Address 0x618c0

ReplaceFileW

Ordinal 1224
Address 0x3b4f0

ReplacePartitionUnit

Ordinal 1225
Address 0x39610

RequestDeviceWakeup

Ordinal 1226
Address 0x38650

RequestWakeupLatency

Ordinal 1227
Address 0x38650

ResetEvent

Ordinal 1228
Address 0x24a10

ResetWriteWatch

Ordinal 1229
Address 0x17ae0

ResizePseudoConsole

Ordinal 1230
Address 0x25320

ResolveDelayLoadedAPI

Ordinal 1231
Address 0xa4714
ForwardName NTDLL.LdrResolveDelayLoadedAPI

ResolveDelayLoadsFromDll

Ordinal 1232
Address 0xa474c
ForwardName NTDLL.LdrResolveDelayLoadsFromDll

ResolveLocaleName

Ordinal 1233
Address 0x20980

RestoreLastError

Ordinal 1234
Address 0xa4791
ForwardName NTDLL.RtlRestoreLastWin32Error

ResumeThread

Ordinal 1235
Address 0x1e060

RtlAddFunctionTable

Ordinal 1236
Address 0x21340

RtlCaptureContext

Ordinal 1237
Address 0x24660

RtlCaptureStackBackTrace

Ordinal 1238
Address 0x21dd0

RtlCompareMemory

Ordinal 1239
Address 0x3b510

RtlCopyMemory

Ordinal 1240
Address 0x3b530

RtlDeleteFunctionTable

Ordinal 1241
Address 0x3b550

RtlFillMemory

Ordinal 1242
Address 0x3b570

RtlInstallFunctionTableCallback

Ordinal 1243
Address 0x3b5a0

RtlLookupFunctionEntry

Ordinal 1244
Address 0x1d290

RtlMoveMemory

Ordinal 1245
Address 0x24690

RtlPcToFileHeader

Ordinal 1246
Address 0x1d360

RtlRaiseException

Ordinal 1247
Address 0x3b5c0

RtlRestoreContext

Ordinal 1248
Address 0x3b5e0

RtlUnwind

Ordinal 1249
Address 0x3b600

RtlUnwindEx

Ordinal 1250
Address 0x1f990

RtlVirtualUnwind

Ordinal 1251
Address 0x1010

RtlZeroMemory

Ordinal 1252
Address 0xa48f0
ForwardName NTDLL.RtlZeroMemory

ScrollConsoleScreenBufferA

Ordinal 1253
Address 0x254a0

ScrollConsoleScreenBufferW

Ordinal 1254
Address 0x254b0

SearchPathA

Ordinal 1255
Address 0x3b620

SearchPathW

Ordinal 1256
Address 0x22170

SetCachedSigningLevel

Ordinal 1257
Address 0x3b640

SetCalendarInfoA

Ordinal 1258
Address 0x4b130

SetCalendarInfoW

Ordinal 1259
Address 0x3b660

SetComPlusPackageInstallStatus

Ordinal 1260
Address 0x42e40

SetCommBreak

Ordinal 1261
Address 0x250d0

SetCommConfig

Ordinal 1262
Address 0x250e0

SetCommMask

Ordinal 1263
Address 0x250f0

SetCommState

Ordinal 1264
Address 0x25100

SetCommTimeouts

Ordinal 1265
Address 0x25110

SetComputerNameA

Ordinal 1266
Address 0x3b680

SetComputerNameEx2W

Ordinal 1267
Address 0x3b6a0

SetComputerNameExA

Ordinal 1268
Address 0x3b6c0

SetComputerNameExW

Ordinal 1269
Address 0x3b6e0

SetComputerNameW

Ordinal 1270
Address 0x3b700

SetConsoleActiveScreenBuffer

Ordinal 1271
Address 0x254c0

SetConsoleCP

Ordinal 1272
Address 0x254d0

SetConsoleCtrlHandler

Ordinal 1273
Address 0x25330

SetConsoleCursor

Ordinal 1274
Address 0x68b90

SetConsoleCursorInfo

Ordinal 1275
Address 0x254e0

SetConsoleCursorMode

Ordinal 1276
Address 0x69100

SetConsoleCursorPosition

Ordinal 1277
Address 0x254f0

SetConsoleDisplayMode

Ordinal 1278
Address 0x25790

SetConsoleFont

Ordinal 1279
Address 0x694d0

SetConsoleHardwareState

Ordinal 1280
Address 0x68bf0

SetConsoleHistoryInfo

Ordinal 1281
Address 0x257a0

SetConsoleIcon

Ordinal 1282
Address 0x69530

SetConsoleInputExeNameA

Ordinal 1283
Address 0xa4b57
ForwardName kernelbase.SetConsoleInputExeNameA

SetConsoleInputExeNameW

Ordinal 1284
Address 0xa4b92
ForwardName kernelbase.SetConsoleInputExeNameW

SetConsoleKeyShortcuts

Ordinal 1285
Address 0x68c50

SetConsoleLocalEUDC

Ordinal 1286
Address 0x69170

SetConsoleMaximumWindowSize

Ordinal 1287
Address 0x21380

SetConsoleMenuClose

Ordinal 1288
Address 0x68ce0

SetConsoleMode

Ordinal 1289
Address 0x25340

SetConsoleNlsMode

Ordinal 1290
Address 0x69230

SetConsoleNumberOfCommandsA

Ordinal 1291
Address 0x257b0

SetConsoleNumberOfCommandsW

Ordinal 1292
Address 0x257c0

SetConsoleOS2OemFormat

Ordinal 1293
Address 0x69290

SetConsoleOutputCP

Ordinal 1294
Address 0x25500

SetConsolePalette

Ordinal 1295
Address 0x68d40

SetConsoleScreenBufferInfoEx

Ordinal 1296
Address 0x25510

SetConsoleScreenBufferSize

Ordinal 1297
Address 0x25520

SetConsoleTextAttribute

Ordinal 1298
Address 0x25530

SetConsoleTitleA

Ordinal 1299
Address 0x25540

SetConsoleTitleW

Ordinal 1300
Address 0x25550

SetConsoleWindowInfo

Ordinal 1301
Address 0x25560

SetCriticalSectionSpinCount

Ordinal 1302
Address 0xa4d48
ForwardName NTDLL.RtlSetCriticalSectionSpinCount

SetCurrentConsoleFontEx

Ordinal 1303
Address 0x257d0

SetCurrentDirectoryA

Ordinal 1304
Address 0x3b720

SetCurrentDirectoryW

Ordinal 1305
Address 0x21300

SetDefaultCommConfigA

Ordinal 1306
Address 0x3d5c0

SetDefaultCommConfigW

Ordinal 1307
Address 0x3d670

SetDefaultDllDirectories

Ordinal 1308
Address 0xa4df4
ForwardName api-ms-win-core-libraryloader-l1-1-0.SetDefaultDllDirectories

SetDllDirectoryA

Ordinal 1309
Address 0x657d0

SetDllDirectoryW

Ordinal 1310
Address 0x20a00

SetDynamicTimeZoneInformation

Ordinal 1311
Address 0x3b740

SetEndOfFile

Ordinal 1312
Address 0x24ed0

SetEnvironmentStringsA

Ordinal 1313
Address 0x670c0

SetEnvironmentStringsW

Ordinal 1314
Address 0x3b760

SetEnvironmentVariableA

Ordinal 1315
Address 0x1dfe0

SetEnvironmentVariableW

Ordinal 1316
Address 0x20960

SetErrorMode

Ordinal 1317
Address 0x1c7b0

SetEvent

Ordinal 1318
Address 0x24a20

SetEventWhenCallbackReturns

Ordinal 1319
Address 0xa4f0f
ForwardName NTDLL.TpCallbackSetEventOnCompletion

SetFileApisToANSI

Ordinal 1320
Address 0x3b780

SetFileApisToOEM

Ordinal 1321
Address 0x3b7a0

SetFileAttributesA

Ordinal 1322
Address 0x24ee0

SetFileAttributesTransactedA

Ordinal 1323
Address 0x62f20

SetFileAttributesTransactedW

Ordinal 1324
Address 0x62f80

SetFileAttributesW

Ordinal 1325
Address 0x24ef0

SetFileBandwidthReservation

Ordinal 1326
Address 0x37280

SetFileCompletionNotificationModes

Ordinal 1327
Address 0x1dee0

SetFileInformationByHandle

Ordinal 1328
Address 0x24f00

SetFileIoOverlappedRange

Ordinal 1329
Address 0x3b7c0

SetFilePointer

Ordinal 1330
Address 0x24f10

SetFilePointerEx

Ordinal 1331
Address 0x24f20

SetFileShortNameA

Ordinal 1332
Address 0x373c0

SetFileShortNameW

Ordinal 1333
Address 0x37410

SetFileTime

Ordinal 1334
Address 0x24f30

SetFileValidData

Ordinal 1335
Address 0x24f40

SetFirmwareEnvironmentVariableA

Ordinal 1336
Address 0x66370

SetFirmwareEnvironmentVariableExA

Ordinal 1337
Address 0x66390

SetFirmwareEnvironmentVariableExW

Ordinal 1338
Address 0x664c0

SetFirmwareEnvironmentVariableW

Ordinal 1339
Address 0x665a0

SetHandleCount

Ordinal 1340
Address 0x21280

SetHandleInformation

Ordinal 1341
Address 0x248b0

SetInformationJobObject

Ordinal 1342
Address 0x1d6a0

SetIoRateControlInformationJobObject

Ordinal 1343
Address 0x5b860

SetLastConsoleEventActive

Ordinal 1344
Address 0xa518a
ForwardName kernelbase.SetLastConsoleEventActive

SetLastError

Ordinal 1345
Address 0x15c50

SetLocalPrimaryComputerNameA

Ordinal 1346
Address 0x5a970

SetLocalPrimaryComputerNameW

Ordinal 1347
Address 0x5a9d0

SetLocalTime

Ordinal 1348
Address 0x3b7e0

SetLocaleInfoA

Ordinal 1349
Address 0x4b220

SetLocaleInfoW

Ordinal 1350
Address 0x3b800

SetMailslotInfo

Ordinal 1351
Address 0x61ee0

SetMessageWaitingIndicator

Ordinal 1352
Address 0x38650

SetNamedPipeAttribute

Ordinal 1353
Address 0x38130

SetNamedPipeHandleState

Ordinal 1354
Address 0x21ee0

SetPriorityClass

Ordinal 1355
Address 0x20af0

SetProcessAffinityMask

Ordinal 1356
Address 0x65f70

SetProcessAffinityUpdateMode

Ordinal 1357
Address 0x241a0

SetProcessDEPPolicy

Ordinal 1358
Address 0x220f0

SetProcessDefaultCpuSets

Ordinal 1359
Address 0xa52ec
ForwardName api-ms-win-core-processthreads-l1-1-3.SetProcessDefaultCpuSets

SetProcessDynamicEHContinuationTargets

Ordinal 1360
Address 0xa5352
ForwardName api-ms-win-core-processthreads-l1-1-4.SetProcessDynamicEHContinuationTargets

SetProcessInformation

Ordinal 1361
Address 0x24860

SetProcessMitigationPolicy

Ordinal 1362
Address 0xa53d0
ForwardName api-ms-win-core-processthreads-l1-1-1.SetProcessMitigationPolicy

SetProcessPreferredUILanguages

Ordinal 1363
Address 0x3b820

SetProcessPriorityBoost

Ordinal 1364
Address 0x21320

SetProcessShutdownParameters

Ordinal 1365
Address 0x206a0

SetProcessWorkingSetSize

Ordinal 1366
Address 0x430a0

SetProcessWorkingSetSizeEx

Ordinal 1367
Address 0x3b840

SetProtectedPolicy

Ordinal 1368
Address 0xa54ac
ForwardName api-ms-win-core-processthreads-l1-1-2.SetProtectedPolicy

SetSearchPathMode

Ordinal 1369
Address 0x37fd0

SetStdHandle

Ordinal 1370
Address 0x201b0

SetStdHandleEx

Ordinal 1371
Address 0x3b860

SetSystemFileCacheSize

Ordinal 1372
Address 0x3b880

SetSystemPowerState

Ordinal 1373
Address 0x38690

SetSystemTime

Ordinal 1374
Address 0x3b8a0

SetSystemTimeAdjustment

Ordinal 1375
Address 0x36cc0

SetTapeParameters

Ordinal 1376
Address 0x42760

SetTapePosition

Ordinal 1377
Address 0x427b0

SetTermsrvAppInstallMode

Ordinal 1378
Address 0x676a0

SetThreadAffinityMask

Ordinal 1379
Address 0x1f090

SetThreadContext

Ordinal 1380
Address 0x3b8c0

SetThreadDescription

Ordinal 1381
Address 0xa55db
ForwardName api-ms-win-core-processthreads-l1-1-3.SetThreadDescription

SetThreadErrorMode

Ordinal 1382
Address 0x1ba80

SetThreadExecutionState

Ordinal 1383
Address 0x209c0

SetThreadGroupAffinity

Ordinal 1384
Address 0x20b10

SetThreadIdealProcessor

Ordinal 1385
Address 0x23ce0

SetThreadIdealProcessorEx

Ordinal 1386
Address 0x3b8e0

SetThreadInformation

Ordinal 1387
Address 0x24870

SetThreadLocale

Ordinal 1388
Address 0x1a0b0

SetThreadPreferredUILanguages

Ordinal 1389
Address 0x1d910

SetThreadPriority

Ordinal 1390
Address 0x1b590

SetThreadPriorityBoost

Ordinal 1391
Address 0x21390

SetThreadSelectedCpuSets

Ordinal 1392
Address 0xa570f
ForwardName api-ms-win-core-processthreads-l1-1-3.SetThreadSelectedCpuSets

SetThreadStackGuarantee

Ordinal 1393
Address 0x1e330

SetThreadToken

Ordinal 1394
Address 0xa5775
ForwardName api-ms-win-core-processthreads-l1-1-0.SetThreadToken

SetThreadUILanguage

Ordinal 1395
Address 0x1c5b0

SetThreadpoolStackInformation

Ordinal 1396
Address 0x3b900

SetThreadpoolThreadMaximum

Ordinal 1397
Address 0xa57f7
ForwardName NTDLL.TpSetPoolMaxThreads

SetThreadpoolThreadMinimum

Ordinal 1398
Address 0x210c0

SetThreadpoolTimer

Ordinal 1399
Address 0xa583f
ForwardName NTDLL.TpSetTimer

SetThreadpoolTimerEx

Ordinal 1400
Address 0xa5865
ForwardName NTDLL.TpSetTimerEx

SetThreadpoolWait

Ordinal 1401
Address 0xa588a
ForwardName NTDLL.TpSetWait

SetThreadpoolWaitEx

Ordinal 1402
Address 0xa58ae
ForwardName NTDLL.TpSetWaitEx

SetTimeZoneInformation

Ordinal 1403
Address 0x3b940

SetTimerQueueTimer

Ordinal 1404
Address 0x43100

SetUmsThreadInformation

Ordinal 1405
Address 0x415b0

SetUnhandledExceptionFilter

Ordinal 1406
Address 0x1fda0

SetUserGeoID

Ordinal 1407
Address 0x53ae0

SetUserGeoName

Ordinal 1408
Address 0x53b00

SetVDMCurrentDirectories

Ordinal 1409
Address 0x40dd0

SetVolumeLabelA

Ordinal 1410
Address 0x666b0

SetVolumeLabelW

Ordinal 1411
Address 0x66760

SetVolumeMountPointA

Ordinal 1412
Address 0x65230

SetVolumeMountPointW

Ordinal 1413
Address 0x23360

SetVolumeMountPointWStub

Ordinal 1414
Address 0x3b960

SetWaitableTimer

Ordinal 1415
Address 0x24a30

SetWaitableTimerEx

Ordinal 1416
Address 0xa59da
ForwardName api-ms-win-core-synch-l1-1-0.SetWaitableTimerEx

SetXStateFeaturesMask

Ordinal 1417
Address 0x3b970

SetupComm

Ordinal 1418
Address 0x25120

ShowConsoleCursor

Ordinal 1419
Address 0x68db0

SignalObjectAndWait

Ordinal 1420
Address 0x3b990

SizeofResource

Ordinal 1421
Address 0x1b380

Sleep

Ordinal 1422
Address 0x1ad40

SleepConditionVariableCS

Ordinal 1423
Address 0xa5a7e
ForwardName api-ms-win-core-synch-l1-2-0.SleepConditionVariableCS

SleepConditionVariableSRW

Ordinal 1424
Address 0xa5ace
ForwardName api-ms-win-core-synch-l1-2-0.SleepConditionVariableSRW

SleepEx

Ordinal 1425
Address 0x24a40

SortCloseHandle

Ordinal 1426
Address 0x1fe00

SortGetHandle

Ordinal 1427
Address 0xa190

StartThreadpoolIo

Ordinal 1428
Address 0xa5b3d
ForwardName NTDLL.TpStartAsyncIoOperation

SubmitThreadpoolWork

Ordinal 1429
Address 0xa5b70
ForwardName NTDLL.TpPostWork

SuspendThread

Ordinal 1430
Address 0x20720

SwitchToFiber

Ordinal 1431
Address 0x251e0

SwitchToThread

Ordinal 1432
Address 0x1b3a0

SystemTimeToFileTime

Ordinal 1433
Address 0x1f670

SystemTimeToTzSpecificLocalTime

Ordinal 1434
Address 0x22150

SystemTimeToTzSpecificLocalTimeEx

Ordinal 1435
Address 0xa5c03
ForwardName api-ms-win-core-timezone-l1-1-0.SystemTimeToTzSpecificLocalTimeEx

TerminateJobObject

Ordinal 1436
Address 0x21030

TerminateProcess

Ordinal 1437
Address 0x20700

TerminateThread

Ordinal 1438
Address 0x3b9b0

TermsrvAppInstallMode

Ordinal 1439
Address 0x225f0

TermsrvConvertSysRootToUserDir

Ordinal 1440
Address 0x67a60

TermsrvCreateRegEntry

Ordinal 1441
Address 0x1d340

TermsrvDeleteKey

Ordinal 1442
Address 0x1df80

TermsrvDeleteValue

Ordinal 1443
Address 0x1df60

TermsrvGetPreSetValue

Ordinal 1444
Address 0x1b6e0

TermsrvGetWindowsDirectoryA

Ordinal 1445
Address 0x220d0

TermsrvGetWindowsDirectoryW

Ordinal 1446
Address 0x1c6c0

TermsrvOpenRegEntry

Ordinal 1447
Address 0x16b30

TermsrvOpenUserClasses

Ordinal 1448
Address 0x1d300

TermsrvRestoreKey

Ordinal 1449
Address 0x686b0

TermsrvSetKeySecurity

Ordinal 1450
Address 0x1baa0

TermsrvSetValueKey

Ordinal 1451
Address 0x1ba60

TermsrvSyncUserIniFileExt

Ordinal 1452
Address 0x686d0

Thread32First

Ordinal 1453
Address 0x21f40

Thread32Next

Ordinal 1454
Address 0x21460

TlsAlloc

Ordinal 1455
Address 0x1c7d0

TlsFree

Ordinal 1456
Address 0x1d320

TlsGetValue

Ordinal 1457
Address 0x154e0

TlsSetValue

Ordinal 1458
Address 0x15b30

Toolhelp32ReadProcessMemory

Ordinal 1459
Address 0x3bde0

TransactNamedPipe

Ordinal 1460
Address 0x3b9d0

TransmitCommChar

Ordinal 1461
Address 0x25130

TryAcquireSRWLockExclusive

Ordinal 1462
Address 0xa5e54
ForwardName NTDLL.RtlTryAcquireSRWLockExclusive

TryAcquireSRWLockShared

Ordinal 1463
Address 0xa5e90
ForwardName NTDLL.RtlTryAcquireSRWLockShared

TryEnterCriticalSection

Ordinal 1464
Address 0xa5ec9
ForwardName NTDLL.RtlTryEnterCriticalSection

TrySubmitThreadpoolCallback

Ordinal 1465
Address 0x21290

TzSpecificLocalTimeToSystemTime

Ordinal 1466
Address 0x3b9f0

TzSpecificLocalTimeToSystemTimeEx

Ordinal 1467
Address 0xa5f48
ForwardName api-ms-win-core-timezone-l1-1-0.TzSpecificLocalTimeToSystemTimeEx

UTRegister

Ordinal 1468
Address 0x38000

UTUnRegister

Ordinal 1469
Address 0x36bd0

UmsThreadYield

Ordinal 1470
Address 0x415f0

UnhandledExceptionFilter

Ordinal 1471
Address 0x3ba10

UnlockFile

Ordinal 1472
Address 0x24f50

UnlockFileEx

Ordinal 1473
Address 0x24f60

UnmapViewOfFile

Ordinal 1474
Address 0x1dfa0

UnmapViewOfFileEx

Ordinal 1475
Address 0xa6004
ForwardName api-ms-win-core-memory-l1-1-1.UnmapViewOfFileEx

UnregisterApplicationRecoveryCallback

Ordinal 1476
Address 0x42f90

UnregisterApplicationRestart

Ordinal 1477
Address 0x3ba30

UnregisterBadMemoryNotification

Ordinal 1478
Address 0x3ba50

UnregisterConsoleIME

Ordinal 1479
Address 0x69070

UnregisterWait

Ordinal 1480
Address 0x13710

UnregisterWaitEx

Ordinal 1481
Address 0x21110

UnregisterWaitUntilOOBECompleted

Ordinal 1482
Address 0x67050

UpdateCalendarDayOfWeek

Ordinal 1483
Address 0x8230

UpdateProcThreadAttribute

Ordinal 1484
Address 0xa611f
ForwardName api-ms-win-core-processthreads-l1-1-0.UpdateProcThreadAttribute

UpdateResourceA

Ordinal 1485
Address 0x492b0

UpdateResourceW

Ordinal 1486
Address 0x49460

VDMConsoleOperation

Ordinal 1487
Address 0x695f0

VDMOperationStarted

Ordinal 1488
Address 0x410a0

VerLanguageNameA

Ordinal 1489
Address 0x21360

VerLanguageNameW

Ordinal 1490
Address 0x204b0

VerSetConditionMask

Ordinal 1491
Address 0xa61dd
ForwardName NTDLL.VerSetConditionMask

VerifyConsoleIoHandle

Ordinal 1492
Address 0x20f00

VerifyScripts

Ordinal 1493
Address 0x3ba70

VerifyVersionInfoA

Ordinal 1494
Address 0x22520

VerifyVersionInfoW

Ordinal 1495
Address 0x183f0

VirtualAlloc

Ordinal 1496
Address 0x184a0

VirtualAllocEx

Ordinal 1497
Address 0x3ba90

VirtualAllocExNuma

Ordinal 1498
Address 0x241e0

VirtualFree

Ordinal 1499
Address 0x1a0d0

VirtualFreeEx

Ordinal 1500
Address 0x3bab0

VirtualLock

Ordinal 1501
Address 0x242f0

VirtualProtect

Ordinal 1502
Address 0x1bc10

VirtualProtectEx

Ordinal 1503
Address 0x3bad0

VirtualQuery

Ordinal 1504
Address 0x1c140

VirtualQueryEx

Ordinal 1505
Address 0x1cf90

VirtualUnlock

Ordinal 1506
Address 0x1c590

WTSGetActiveConsoleSessionId

Ordinal 1507
Address 0x20440

WaitCommEvent

Ordinal 1508
Address 0x25140

WaitForDebugEvent

Ordinal 1509
Address 0x3baf0

WaitForDebugEventEx

Ordinal 1510
Address 0xa6331
ForwardName api-ms-win-core-debug-l1-1-2.WaitForDebugEventEx

WaitForMultipleObjects

Ordinal 1511
Address 0x24a50

WaitForMultipleObjectsEx

Ordinal 1512
Address 0x24a60

WaitForSingleObject

Ordinal 1513
Address 0x24a70

WaitForSingleObjectEx

Ordinal 1514
Address 0x24a80

WaitForThreadpoolIoCallbacks

Ordinal 1515
Address 0xa63d9
ForwardName NTDLL.TpWaitForIoCompletion

WaitForThreadpoolTimerCallbacks

Ordinal 1516
Address 0xa6415
ForwardName NTDLL.TpWaitForTimer

WaitForThreadpoolWaitCallbacks

Ordinal 1517
Address 0xa6449
ForwardName NTDLL.TpWaitForWait

WaitForThreadpoolWorkCallbacks

Ordinal 1518
Address 0xa647c
ForwardName NTDLL.TpWaitForWork

WaitNamedPipeA

Ordinal 1519
Address 0x609d0

WaitNamedPipeW

Ordinal 1520
Address 0x3bb10

WakeAllConditionVariable

Ordinal 1521
Address 0xa64c7
ForwardName NTDLL.RtlWakeAllConditionVariable

WakeConditionVariable

Ordinal 1522
Address 0xa64ff
ForwardName NTDLL.RtlWakeConditionVariable

WerGetFlags

Ordinal 1523
Address 0x42fb0

WerGetFlagsWorker

Ordinal 1524
Address 0x42fb0

WerRegisterAdditionalProcess

Ordinal 1525
Address 0x3bb30

WerRegisterAppLocalDump

Ordinal 1526
Address 0x3bb50

WerRegisterCustomMetadata

Ordinal 1527
Address 0x3bb70

WerRegisterExcludedMemoryBlock

Ordinal 1528
Address 0x3bb90

WerRegisterFile

Ordinal 1529
Address 0x20420

WerRegisterFileWorker

Ordinal 1530
Address 0x42fc0

WerRegisterMemoryBlock

Ordinal 1531
Address 0x20680

WerRegisterMemoryBlockWorker

Ordinal 1532
Address 0x42fd0

WerRegisterRuntimeExceptionModule

Ordinal 1533
Address 0x20820

WerRegisterRuntimeExceptionModuleWorker

Ordinal 1534
Address 0x42fe0

WerSetFlags

Ordinal 1535
Address 0x1cb70

WerSetFlagsWorker

Ordinal 1536
Address 0x1cb70

WerUnregisterAdditionalProcess

Ordinal 1537
Address 0x3bbb0

WerUnregisterAppLocalDump

Ordinal 1538
Address 0x3bbd0

WerUnregisterCustomMetadata

Ordinal 1539
Address 0x3bbf0

WerUnregisterExcludedMemoryBlock

Ordinal 1540
Address 0x3bc10

WerUnregisterFile

Ordinal 1541
Address 0x20400

WerUnregisterFileWorker

Ordinal 1542
Address 0x42ff0

WerUnregisterMemoryBlock

Ordinal 1543
Address 0x21b40

WerUnregisterMemoryBlockWorker

Ordinal 1544
Address 0x43000

WerUnregisterRuntimeExceptionModule

Ordinal 1545
Address 0x3bc30

WerUnregisterRuntimeExceptionModuleWorker

Ordinal 1546
Address 0x43010

WerpGetDebugger

Ordinal 1547
Address 0x6c050

WerpInitiateRemoteRecovery

Ordinal 1548
Address 0x43020

WerpLaunchAeDebug

Ordinal 1549
Address 0x6ca40

WerpNotifyLoadStringResourceWorker

Ordinal 1550
Address 0x1b5b0

WerpNotifyUseStringResourceWorker

Ordinal 1551
Address 0x1b5b0

WideCharToMultiByte

Ordinal 1552
Address 0x15ad0

WinExec

Ordinal 1553
Address 0x65fc0

Wow64DisableWow64FsRedirection

Ordinal 1554
Address 0x3bc50

Wow64EnableWow64FsRedirection

Ordinal 1555
Address 0x21580

Wow64GetThreadContext

Ordinal 1556
Address 0x3bc70

Wow64GetThreadSelectorEntry

Ordinal 1557
Address 0x36db0

Wow64RevertWow64FsRedirection

Ordinal 1558
Address 0x3bc90

Wow64SetThreadContext

Ordinal 1559
Address 0x3bcb0

Wow64SuspendThread

Ordinal 1560
Address 0x3bcd0

WriteConsoleA

Ordinal 1561
Address 0x25350

WriteConsoleInputA

Ordinal 1562
Address 0x25570

WriteConsoleInputVDMA

Ordinal 1563
Address 0x68df0

WriteConsoleInputVDMW

Ordinal 1564
Address 0x68e80

WriteConsoleInputW

Ordinal 1565
Address 0x25580

WriteConsoleOutputA

Ordinal 1566
Address 0x25590

WriteConsoleOutputAttribute

Ordinal 1567
Address 0x255a0

WriteConsoleOutputCharacterA

Ordinal 1568
Address 0x255b0

WriteConsoleOutputCharacterW

Ordinal 1569
Address 0x255c0

WriteConsoleOutputW

Ordinal 1570
Address 0x255d0

WriteConsoleW

Ordinal 1571
Address 0x25360

WriteFile

Ordinal 1572
Address 0x24f70

WriteFileEx

Ordinal 1573
Address 0x24f80

WriteFileGather

Ordinal 1574
Address 0x24f90

WritePrivateProfileSectionA

Ordinal 1575
Address 0x5f8d0

WritePrivateProfileSectionW

Ordinal 1576
Address 0x23d00

WritePrivateProfileStringA

Ordinal 1577
Address 0x5f940

WritePrivateProfileStringW

Ordinal 1578
Address 0x17a90

WritePrivateProfileStructA

Ordinal 1579
Address 0x5f9b0

WritePrivateProfileStructW

Ordinal 1580
Address 0x5fb20

WriteProcessMemory

Ordinal 1581
Address 0x3bcf0

WriteProfileSectionA

Ordinal 1582
Address 0x5fc90

WriteProfileSectionW

Ordinal 1583
Address 0x5fca0

WriteProfileStringA

Ordinal 1584
Address 0x5fcb0

WriteProfileStringW

Ordinal 1585
Address 0x5fcc0

WriteTapemark

Ordinal 1586
Address 0x42820

ZombifyActCtx

Ordinal 1587
Address 0x3bd10

ZombifyActCtxWorker

Ordinal 1588
Address 0x42dc0

__C_specific_handler

Ordinal 1589
Address 0xa6b46
ForwardName NTDLL.__C_specific_handler

__chkstk

Ordinal 1590
Address 0xa6b6a
ForwardName NTDLL.__chkstk

__misaligned_access

Ordinal 1591
Address 0xa6b8d
ForwardName NTDLL.__misaligned_access

_hread

Ordinal 1592
Address 0x17c60

_hwrite

Ordinal 1593
Address 0x687e0

_lclose

Ordinal 1594
Address 0x1c5d0

_lcreat

Ordinal 1595
Address 0x686f0

_llseek

Ordinal 1596
Address 0x17c30

_local_unwind

Ordinal 1597
Address 0xa6bdc
ForwardName NTDLL._local_unwind

_lopen

Ordinal 1598
Address 0x68760

_lread

Ordinal 1599
Address 0x17c60

_lwrite

Ordinal 1600
Address 0x687e0

lstrcat

Ordinal 1601
Address 0x20060

lstrcatA

Ordinal 1602
Address 0x20060

lstrcatW

Ordinal 1603
Address 0x68830

lstrcmp

Ordinal 1604
Address 0x1c420

lstrcmpA

Ordinal 1605
Address 0x1c420

lstrcmpW

Ordinal 1606
Address 0x1b710

lstrcmpi

Ordinal 1607
Address 0x1b2a0

lstrcmpiA

Ordinal 1608
Address 0x1b2a0

lstrcmpiW

Ordinal 1609
Address 0x17b40

lstrcpy

Ordinal 1610
Address 0x1e2a0

lstrcpyA

Ordinal 1611
Address 0x1e2a0

lstrcpyW

Ordinal 1612
Address 0x21df0

lstrcpyn

Ordinal 1613
Address 0x3bd30

lstrcpynA

Ordinal 1614
Address 0x3bd30

lstrcpynW

Ordinal 1615
Address 0x20f10

lstrlen

Ordinal 1616
Address 0x1aa50

lstrlenA

Ordinal 1617
Address 0x1aa50

lstrlenW

Ordinal 1618
Address 0x16fa0

timeBeginPeriod

Ordinal 1619
Address 0x1d930

timeEndPeriod

Ordinal 1620
Address 0x1c9b0

timeGetDevCaps

Ordinal 1621
Address 0x22060

timeGetSystemTime

Ordinal 1622
Address 0x68880

timeGetTime

Ordinal 1623
Address 0x1b9c0

uaw_lstrcmpW

Ordinal 1624
Address 0x1b710

uaw_lstrcmpiW

Ordinal 1625
Address 0x17b40

uaw_lstrlenW

Ordinal 1626
Address 0x365f0

uaw_wcschr

Ordinal 1627
Address 0x36640

uaw_wcscpy

Ordinal 1628
Address 0x36670

uaw_wcsicmp

Ordinal 1629
Address 0x366a0

uaw_wcslen

Ordinal 1630
Address 0x366c0

uaw_wcsrchr

Ordinal 1631
Address 0x366f0

1

Type MUI
Language English - United States
Codepage UNKNOWN
Size 0xc8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.70306
MD5 6a9f5fbd6cf1aad0ba41137be527777d
SHA1 ed873ab33020642f2efd39f6e18b449c01b50474
SHA256 92c6c9e47e69e57643f73bea062ad64f280320410eca9cf43841fee659509223
SHA3 f7f3c5070aa3065f4435761dfeab6f1daabd2d04a7fce6791352613e1a4a00cf

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x3a4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.49722
MD5 2297a045d30364d04aa99ae2cb8ad92a
SHA1 2e8f04173b02d87bbe5545ac3d9c10bcfbf01e6a
SHA256 ddf119467aa258ad8160e46ed5c319696f507d16cab173b6332d73f70dfdb7f1
SHA3 aca68a9ee6d3bd7e43c914aa5af3739b21232d721b8ff5d071c07be1d110f435

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 10.0.19041.292
ProductVersion 10.0.19041.292
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_DLL
Language English - United States
CompanyName Microsoft Corporation
FileDescription Windows NT BASE API Client DLL
FileVersion (#2) 10.0.19041.292 (WinBuild.160101.0800)
InternalName kernel32
LegalCopyright © Microsoft Corporation. All rights reserved.
OriginalFilename kernel32
ProductName Microsoft® Windows® Operating System
ProductVersion (#2) 10.0.19041.292
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2031-Mar-30 07:12:41
Version 0.0
SizeofData 37
AddressOfRawData 0x92130
PointerToRawData 0x90930
Referenced File kernel32.pdb

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2031-Mar-30 07:12:41
Version 0.0
SizeofData 1332
AddressOfRawData 0x92158
PointerToRawData 0x90958

UNKNOWN

Characteristics 0
TimeDateStamp 2031-Mar-30 07:12:41
Version 0.0
SizeofData 36
AddressOfRawData 0x9268c
PointerToRawData 0x90e8c

UNKNOWN (#2)

Characteristics 0
TimeDateStamp 2031-Mar-30 07:12:41
Version 0.0
SizeofData 4
AddressOfRawData 0x926b0
PointerToRawData 0x90eb0

TLS Callbacks

Load Configuration

Size 0x118
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x1800b2220
GuardCFCheckFunctionPointer 6442988048
GuardCFDispatchFunctionPointer 0
GuardCFFunctionTable 0
GuardCFFunctionCount 0
GuardFlags (EMPTY)
CodeIntegrity.Flags 0
CodeIntegrity.Catalog 0
CodeIntegrity.CatalogOffset 0
CodeIntegrity.Reserved 0
GuardAddressTakenIatEntryTable 0
GuardAddressTakenIatEntryCount 0
GuardLongJumpTargetTable 0
GuardLongJumpTargetCount 0

RICH Header

XOR Key 0x8aaadaa7
Unmarked objects 0
Imports (27412) 4
Imports (VS2008 SP1 build 30729) 193
Total imports 1322
C objects (27412) 9
ASM objects (27412) 3
Exports (27412) 1
269 (27412) 209
Resource objects (27412) 1
Linker (27412) 1

Errors

Leave a comment

No comments yet.